{
  "module": "platform",
  "surface": "1edtech",
  "deliverable": "data_dictionary",
  "title": "TimeBack Platform Data Dictionary",
  "architectureUrl": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture",
  "benchmarkUrl": "https://platform3-24kpiksyo-andymontgomery-9773s-projects.vercel.app/data_dictionary",
  "generatedAt": "2026-08-10T12:39:23Z",
  "upstreamArtifacts": [
    {
      "id": "platform-architecture",
      "title": "Platform Architecture",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture",
      "localPath": "loop/platform/artifacts/1edtech/architecture",
      "usedFor": "PITD anchors, platform shared-table decisions, QTI reconciliation requirements, and dictionary convention policy."
    },
    {
      "id": "incept-producer-surface-decision",
      "title": "Incept Platform3 Producer Surface Decision",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface",
      "localPath": "loop/context/incept-platform3-surface-decision.md",
      "usedFor": "PITD-032 producer-surface boundary, governed incept object list, raw-DB/API convergence rule, and direct-DB deprecation rule."
    },
    {
      "id": "ap-one-platform-capabilities-decision",
      "title": "AP One Platform Capability Contract",
      "url": "local decision",
      "localPath": "loop/context/ap-one-platform-capabilities-decision.md",
      "usedFor": "Issue #1128 QTI structured-response, Results item-calibration, hosted producer-quality verdict, and Events/Analytics lab plus fluency semantics."
    },
    {
      "id": "incept-catalog-snapshot",
      "title": "Incept Postgres Catalog Snapshot",
      "url": "local Supabase catalog probe",
      "localPath": "loop/platform/artifacts/1edtech/data_dictionary/source/incept-schema-catalog.json",
      "usedFor": "Actual table/view columns, constraints, indexes, comments, and view definitions for the Incept producer-surface dictionary coverage."
    },
    {
      "id": "qti-1edtech-architecture",
      "title": "QTI 1EdTech Architecture",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/qti/1edtech/architecture",
      "localPath": "loop/qti/artifacts/1edtech/architecture",
      "usedFor": "Approved QTI 1EdTech architecture truth. Current QTI 1EdTech release status still comes from loop/qti/state.json, not from this stable architecture URL."
    },
    {
      "id": "qti-1edtech-data-dictionary",
      "title": "QTI 1EdTech Data Dictionary",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/qti/1edtech/data_dictionary",
      "localPath": "loop/qti/artifacts/1edtech/data_dictionary",
      "usedFor": "Approved QTI field-level pattern and predecessor qti.tenant/idempotency evidence. Current QTI 1EdTech release status still comes from loop/qti/state.json, not from this stable dictionary URL."
    },
    {
      "id": "qti-alpha-data-dictionary",
      "title": "QTI Alpha Data Dictionary",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/qti/alpha/data_dictionary/",
      "localPath": "loop/qti/artifacts/alpha/data_dictionary",
      "usedFor": "Approved provenance mapping, Alpha cut/restrict/rename/extend labels, public field naming, and studentRef privacy wording."
    },
    {
      "id": "oneroster-1edtech-data-dictionary",
      "title": "OneRoster 1EdTech Data Dictionary",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/oneroster/1edtech/data_dictionary",
      "localPath": "loop/oneroster/artifacts/1edtech/data_dictionary",
      "usedFor": "Current approved OneRoster module status and module_key semantics for shared audit/idempotency rows."
    },
    {
      "id": "caliper-1edtech-data-dictionary",
      "title": "Caliper 1EdTech Data Dictionary",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/caliper/1edtech/data_dictionary",
      "localPath": "loop/caliper/artifacts/1edtech/data_dictionary",
      "usedFor": "Current approved Caliper module status and module_key semantics for shared audit/idempotency rows."
    },
    {
      "id": "case-1edtech-data-dictionary",
      "title": "CASE 1EdTech Data Dictionary",
      "url": "https://platform3-andymontgomery-9773s-projects.vercel.app/case/1edtech/data_dictionary",
      "localPath": "loop/case/artifacts/1edtech/data_dictionary",
      "usedFor": "Current CASE module release state, CASE resource ownership, and module_key semantics for shared audit/idempotency rows."
    },
    {
      "id": "case-idempotency-claim-decision",
      "title": "CASE 1EdTech Durable Idempotency Ownership",
      "url": "local decision",
      "localPath": "loop/context/case-idempotency-claim-decision.md",
      "usedFor": "Issue #1454 CASE tenant/key claim scope, atomic mutation-and-receipt transaction, stale-owner fencing, commit-uncertain policy, and local-ledger migration boundary."
    },
    {
      "id": "benchmark-data-dictionary",
      "title": "Data Dictionary Eval Pair Benchmark",
      "url": "https://platform3-24kpiksyo-andymontgomery-9773s-projects.vercel.app/data_dictionary",
      "localPath": "loop/context/benchmarks/data_dictionary.html",
      "usedFor": "Customer-eval persona and scoring-rubric failure categories for migration/query-grade data dictionaries."
    },
    {
      "id": "rfc-8785-jcs",
      "title": "RFC 8785 JSON Canonicalization Scheme",
      "url": "https://www.rfc-editor.org/rfc/rfc8785",
      "localPath": "fetched live from RFC Editor",
      "usedFor": "Named canonical JSON profile for request_hash so idempotency conflict checks are reproducible across middleware implementations."
    }
  ],
  "summary": {
    "schema": "platform",
    "sharedTables": [
      "platform.tenant",
      "platform.idempotency_key",
      "platform.audit_log",
      "platform.end_user_identity_binding",
      "platform.end_user_session",
      "platform.producer_credential_grant",
      "platform.producer_credential"
    ],
    "fieldCount": 93,
    "inceptObjectCount": 18,
    "inceptFieldCount": 392,
    "enumSetCount": 10,
    "conventionCount": 13,
    "guardrailRuleCount": 8,
    "searchableSectionCount": 65,
    "moduleReleaseStatusCount": 6,
    "qtiReconciliationCount": 6
  },
  "tables": [
    {
      "name": "platform.tenant",
      "title": "Tenant",
      "short": "The shared school, district, publisher, application, or workspace boundary used by every module.",
      "purpose": "A tenant is the platform-wide owner of content, learner runtime records, integrations, and API access. QTI used qti.tenant as the first-module pattern; this table promotes that boundary so QTI, OneRoster, Caliper, CASE, and future modules all point to the same customer/workspace row.",
      "lifecycle": "Created in provisioning before any module writes tenant-scoped data. Moves to active when authentication and operational setup are complete; the same idempotent create may start active only when the exact platform-operator tenant principal has the service role plus platform:tenant:create or platform:* scope and setup is already complete. Other create authorities remain provisioning-only. Suspended pauses writes, and archived retains the workspace for history but closes ordinary writes. Learner-runtime deletion is handled by module tables, not by deleting the tenant row.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "PITD-003 makes platform.tenant the cross-module tenant truth and PITD-002 says shared concepts live in platform.*.",
      "itds": [
        {
          "id": "PITD-002",
          "title": "Module Schemas And Shared Platform Schema",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-002-module-schema-boundaries"
        },
        {
          "id": "PITD-003",
          "title": "Shared Tenant Model",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
        },
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        }
      ],
      "qtiReconciliation": "Supersedes qti.tenant as cross-module truth. The platform implementation must either migrate qti.tenant rows into platform.tenant and add QTI foreign keys, or expose qti.tenant as a compatibility view over platform.tenant before claiming full platform/QTI conformance.",
      "primaryKey": "tenant_id",
      "relationships": [
        "Parent of platform.idempotency_key through platform.idempotency_key.tenant_id.",
        "Parent of platform.audit_log through platform.audit_log.tenant_id.",
        "Future module tenant-scoped tables must reference platform.tenant(tenant_id) rather than creating module-local tenant tables.",
        "QTI predecessor: qti.tenant(tenant_id) is reconciled to this table by migration or compatibility view."
      ],
      "constraints": [
        "tenant_key is unique and stable across platform.tenant.",
        "status must be one of tenant_status.",
        "metadata must be a JSON object and must not contain direct learner/parent PII, credentials, Bearer tokens, raw JWTs, or contact details.",
        "updated_at must be greater than or equal to created_at."
      ],
      "indexes": [
        "primary key (tenant_id)",
        "unique (tenant_key)",
        "index (status)",
        "index (updated_at)"
      ],
      "ddl": "create table platform.tenant (\n  tenant_id uuid primary key default gen_random_uuid(),\n  tenant_key text not null unique,\n  display_name text not null,\n  status text not null default 'provisioning',\n  metadata jsonb not null default '{}'::jsonb,\n  created_at timestamptz not null default now(),\n  updated_at timestamptz not null default now(),\n  constraint tenant_key_format_ck\n    check (tenant_key ~ '^[a-z0-9]([a-z0-9-]{1,62}[a-z0-9])$'),\n  constraint tenant_display_name_present_ck\n    check (length(btrim(display_name)) between 1 and 160),\n  constraint tenant_status_ck\n    check (status in ('provisioning', 'active', 'suspended', 'archived')),\n  constraint tenant_metadata_object_ck\n    check (jsonb_typeof(metadata) = 'object'),\n  constraint tenant_updated_after_created_ck\n    check (updated_at >= created_at)\n);\n\ncreate index tenant_status_idx on platform.tenant(status);\ncreate index tenant_updated_at_idx on platform.tenant(updated_at);",
      "invalidExamples": [
        "tenant_key = 'North Valley' because keys must be lowercase slug values.",
        "metadata contains a student email, parent phone number, raw JWT subject, access token, or SIS identifier.",
        "status = 'enabled' because the only active state is active.",
        "A module table references qti.tenant instead of platform.tenant after the platform compatibility bridge exists."
      ],
      "example": {
        "tenant_id": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
        "tenant_key": "north-valley",
        "display_name": "North Valley School District",
        "status": "active",
        "metadata": {
          "region": "us-east",
          "externalRefs": [
            {
              "system": "crm",
              "ref": "acct_7x9"
            }
          ]
        },
        "created_at": "2026-05-21T12:00:00Z",
        "updated_at": "2026-05-21T12:00:00Z"
      },
      "queries": [
        "select tenant_id, status from platform.tenant where tenant_key = $1;",
        "insert into platform.tenant (tenant_key, display_name, status, metadata) values ($1, $2, 'provisioning', '{}'::jsonb) returning tenant_id;",
        "select t.tenant_key, count(a.audit_log_id) from platform.tenant t left join platform.audit_log a using (tenant_id) where t.status = 'active' group by t.tenant_key;"
      ],
      "fields": [
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable database identifier for one customer/workspace boundary. This is the value module tables reference and tenant-scoped JWTs must match.",
          "constraints": "Must be a valid PostgreSQL UUID and unique as the primary key.",
          "allowedValues": null,
          "relationship": "Referenced by platform.idempotency_key.tenant_id, platform.audit_log.tenant_id, and future module tenant_id fields. One tenant has many module records.",
          "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
          "invalidWhen": "Not parseable as UUID, reused by another tenant, copied into learner-facing content as identity text, or replaced by tenant_key in foreign keys.",
          "edgeCases": "QTI reconciliation must preserve existing qti.tenant tenant_id values or provide a deterministic mapping table during migration.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-003 required tenant_id in platform.tenant.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
          },
          "anchor": "field-platform-tenant-tenant-id"
        },
        {
          "name": "tenant_key",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Unique",
          "meaning": "Human-stable lookup key for routes, local tooling, logs, and examples. It is a convenience key, not an authorization secret.",
          "constraints": "3 to 64 characters. Lowercase ASCII letters, digits, and hyphens only. Must start and end with a letter or digit. Unique across platform.tenant.",
          "allowedValues": null,
          "relationship": "No foreign keys should point at tenant_key; use tenant_id for joins.",
          "example": "north-valley",
          "invalidWhen": "Blank, uppercase, contains spaces, contains an email/domain secret, duplicates another tenant, or is used as proof of authorization.",
          "edgeCases": "A renamed school may keep its tenant_key stable and update display_name instead; changing tenant_key is a migration because URLs and examples may depend on it.",
          "provenance": {
            "label": "Platform shared",
            "basis": "QTI's qti.tenant.tenant_key pattern promoted into platform tenant lookup.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
          },
          "anchor": "field-platform-tenant-tenant-key"
        },
        {
          "name": "display_name",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Customer-facing label shown in admin tools and documentation examples.",
          "constraints": "1 to 160 visible characters after trimming. Required. Must not be used for uniqueness, routing, authorization, or joins.",
          "allowedValues": null,
          "relationship": "None. It describes the tenant row and can change without changing tenant_id.",
          "example": "North Valley School District",
          "invalidWhen": "Null, blank, over 160 characters, used as an authorization key, or copied into module records instead of joining to platform.tenant.",
          "edgeCases": "The name may contain a school or district name. Do not store student, parent, or teacher contact details here.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-003 required display_name in platform.tenant.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
          },
          "anchor": "field-platform-tenant-display-name"
        },
        {
          "name": "status",
          "type": "text",
          "required": true,
          "default": "'provisioning'",
          "key": null,
          "meaning": "Tenant lifecycle state that tells modules whether ordinary tenant-scoped writes may proceed.",
          "constraints": "Must satisfy tenant_status_allowed: provisioning, active, suspended, or archived.",
          "allowedValues": "tenant_status",
          "relationship": "No foreign key. Modules read this before accepting customer writes.",
          "example": "active",
          "invalidWhen": "Outside tenant_status, null, manually changed without an audit row explaining the administrative action, or created active without the exact platform-operator tenant principal, service role, and platform:tenant:create or platform:* scope.",
          "edgeCases": "Create defaults to provisioning. Direct active creation is the existing idempotent create with the exact platform-operator tenant principal, Platform service role, and explicit tenant-create or wildcard scope after setup is complete; reviewer, writer, demo, and every tenant-bound service credential remain provisioning-only. Suspended and archived tenants can still be read by authorized support or export flows if the customer website documents that behavior.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-003 left status to the data dictionary; PITD-005 and PITD-009 require auditable tenant scope.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
          },
          "anchor": "field-platform-tenant-status"
        },
        {
          "name": "metadata",
          "type": "jsonb",
          "required": true,
          "default": "'{}'::jsonb",
          "key": null,
          "meaning": "Small redacted operational facts about the tenant that do not deserve first-class columns yet.",
          "constraints": "Must be a JSON object. Recommended top-level keys are region, externalRefs, notes, and featureFlags. Must not contain secrets, raw JWTs, direct learner/parent PII, raw package bytes, IP addresses, or user agents.",
          "allowedValues": null,
          "relationship": "None. External references inside metadata are diagnostic and cannot replace tenant_id joins.",
          "example": "{\"region\":\"us-east\",\"externalRefs\":[{\"system\":\"crm\",\"ref\":\"acct_7x9\"}]}",
          "invalidWhen": "Null, non-object JSON, stores a student email/phone/name/SIS ID, stores credentials, or becomes the only place a required module relationship is recorded.",
          "edgeCases": "If a metadata key becomes required for authorization, billing, or module behavior, promote it to a typed column through a new data-dictionary attempt and migration.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-003 required metadata; PITD-008 limits PII in shared tables.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
          },
          "anchor": "field-platform-tenant-metadata"
        },
        {
          "name": "created_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Timestamp when the tenant row was inserted.",
          "constraints": "Required timestamp with time zone. Stored in UTC by PostgreSQL/Supabase conventions.",
          "allowedValues": null,
          "relationship": "None.",
          "example": "2026-05-21T12:00:00Z",
          "invalidWhen": "Null, manually backdated without migration evidence, or compared as local wall time.",
          "edgeCases": "Bulk migrations from qti.tenant may preserve an older source created_at only when the migration notes explain the source.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-017 requires DDL comments and lifecycle timestamps.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-017-migrations-and-ddl-discipline"
          },
          "anchor": "field-platform-tenant-created-at"
        },
        {
          "name": "updated_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Timestamp when the tenant row was last changed.",
          "constraints": "Required timestamp with time zone. Must be greater than or equal to created_at. Updated on every display_name, status, or metadata change.",
          "allowedValues": null,
          "relationship": "None.",
          "example": "2026-05-21T12:00:00Z",
          "invalidWhen": "Null, earlier than created_at, or left unchanged after a tenant status or metadata mutation.",
          "edgeCases": "Audit rows remain the detailed history; updated_at is only the latest-row freshness indicator.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-017 requires forward-only migrations and observable shared state.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-017-migrations-and-ddl-discipline"
          },
          "anchor": "field-platform-tenant-updated-at"
        }
      ],
      "anchor": "table-platform-tenant",
      "sqlComments": "comment on table platform.tenant is 'A tenant is the platform-wide owner of content, learner runtime records, integrations, and API access. QTI used qti.tenant as the first-module pattern; this table promotes that boundary so QTI, OneRoster, Caliper, CASE, and future modules all point to the same customer/workspace row.';\ncomment on column platform.tenant.tenant_id is 'Stable database identifier for one customer/workspace boundary. This is the value module tables reference and tenant-scoped JWTs must match.';\ncomment on column platform.tenant.tenant_key is 'Human-stable lookup key for routes, local tooling, logs, and examples. It is a convenience key, not an authorization secret.';\ncomment on column platform.tenant.display_name is 'Customer-facing label shown in admin tools and documentation examples.';\ncomment on column platform.tenant.status is 'Tenant lifecycle state that tells modules whether ordinary tenant-scoped writes may proceed.';\ncomment on column platform.tenant.metadata is 'Small redacted operational facts about the tenant that do not deserve first-class columns yet.';\ncomment on column platform.tenant.created_at is 'Timestamp when the tenant row was inserted.';\ncomment on column platform.tenant.updated_at is 'Timestamp when the tenant row was last changed.';"
    },
    {
      "name": "platform.idempotency_key",
      "title": "Idempotency key",
      "short": "Shared retry ledger for customer-visible create, import, upload, export-job, and asynchronous command operations.",
      "purpose": "This table records the first request to claim an Idempotency-Key within a precise Platform-owned scope. The default is tenant/module/surface/operation; explicit route profiles such as CASE 1EdTech may enforce a stricter tenant/module/surface/key scope. Later matching requests replay the original safe result, while key reuse with a different canonical request returns 409 before side effects.",
      "lifecycle": "Inserted as in_progress before a mutation performs side effects. Updated to completed or failed_permanent when a replayable final outcome exists, failed_transient when no stable result can be replayed but retry is proven safe, commit_uncertain when side-effect commit state is unknown and non-reclaimable, and expired after the documented replay window. While in_progress or failed_transient, locked_until is the lease boundary: future locks reject concurrent duplicates, stale same-hash locks may be reclaimed only under the safe-retry precondition, and different hashes remain conflicts. Cleanup may retain expired rows for audit while making them non-replayable.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "PITD-007 promotes QTI's package idempotency pattern into a platform-wide ledger.",
      "itds": [
        {
          "id": "PITD-007",
          "title": "Idempotency And Optimistic Concurrency",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
        },
        {
          "id": "PITD-006",
          "title": "HTTP Envelope, Status, And Problem Errors",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-006-http-envelope-and-errors"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ],
      "qtiReconciliation": "Promotes qti.content_package.idempotency_key from a package-specific field into a reusable platform ledger. QTI package rows may keep their package-specific key copy for query compatibility, but replay and conflict behavior belongs to platform.idempotency_key.",
      "primaryKey": "idempotency_key_id",
      "relationships": [
        "Belongs to one platform.tenant.",
        "May be referenced by many platform.audit_log rows through platform.audit_log.idempotency_key_id.",
        "Module-specific rows may store their own resource identifier; this table records retry state and safe replay data, not the source of record for module resources."
      ],
      "constraints": [
        "Unique scope: tenant_id, module, surface, method, route_template, operation_id, idempotency_key.",
        "CASE 1EdTech route-profile scope: unique tenant_id, module=case, surface=1edtech, idempotency_key. Method, route, operation, concrete resource identity, body, and If-Match remain part of its canonical hash, so cross-route or cross-resource reuse conflicts.",
        "request_hash must be sha256:<64 lowercase hex characters>.",
        "Default request_hash canonical input order is [\"v1\", METHOD, route_template, tenant_id, module, surface, operation_id, canonical_payload_sha256, canonical_header_sha256]; only an explicit Platform-owned route profile may pin a different exact canonical input for deployed compatibility.",
        "By default, locked_until drives the live-lock and stale-lock-reclaim rules: same hash plus future lock returns 409 idempotency_in_progress with Retry-After; same hash plus stale lock can be reclaimed by one FOR UPDATE worker only when the mutation is proven not to have committed or is internally idempotent; different hash is always conflict; commit_uncertain rows are never reclaimable. An explicit Platform-owned route profile may choose a more conservative non-reclaimable terminal response and a documented live progress status.",
        "response_status must be null while status is in_progress, failed_transient, or commit_uncertain and between 100 and 599 when present.",
        "response_body must be null or a redacted JSON object or array safe to replay to the same tenant.",
        "response_headers must be a redacted JSON object; canonical_request_hash and lease_token fence protocol-specific ownership without turning request IDs into owner credentials.",
        "expires_at must be later than created_at."
      ],
      "indexes": [
        "primary key (idempotency_key_id)",
        "unique (tenant_id, module, surface, method, route_template, operation_id, idempotency_key)",
        "partial unique (tenant_id, module, surface, idempotency_key) where module=case and surface=1edtech",
        "index (tenant_id, expires_at)",
        "index (status, locked_until) for stale-lock-reclaim and cleanup scans",
        "index (request_hash)"
      ],
      "ddl": "create table platform.idempotency_key (\n  idempotency_key_id uuid primary key default gen_random_uuid(),\n  tenant_id uuid not null references platform.tenant(tenant_id),\n  module text not null,\n  surface text not null,\n  method text not null,\n  route_template text not null,\n  operation_id text not null,\n  idempotency_key text not null,\n  request_hash text not null,\n  canonical_request_hash text,\n  claim_protocol text,\n  status text not null default 'in_progress',\n  response_status integer,\n  response_body jsonb,\n  response_headers jsonb not null default '{}'::jsonb,\n  resource_type text,\n  resource_id text,\n  first_request_id text not null,\n  lease_token text,\n  locked_until timestamptz,\n  expires_at timestamptz not null,\n  created_at timestamptz not null default now(),\n  updated_at timestamptz not null default now(),\n  constraint idempotency_module_ck\n    check (module in ('platform', 'incept', 'qti', 'oneroster', 'caliper', 'case', 'nweamap', 'ed_fi', 'people_and_orgs', 'curriculum', 'content', 'events', 'results', 'analytics')),\n  constraint idempotency_surface_ck\n    check (surface in ('platform', '1edtech', 'alpha')),\n  constraint idempotency_method_ck\n    check (method in ('POST', 'PUT', 'PATCH', 'DELETE')),\n  constraint idempotency_route_template_ck\n    check (route_template like '/%' and position('?' in route_template) = 0),\n  constraint idempotency_operation_id_ck\n    check (operation_id ~ '^[a-z0-9][a-z0-9._-]{0,119}$'),\n  constraint idempotency_key_length_ck\n    check (length(btrim(idempotency_key)) between 1 and 128),\n  constraint idempotency_request_hash_ck\n    check (request_hash ~ '^sha256:[0-9a-f]{64}$'),\n  constraint idempotency_status_ck\n    check (status in ('in_progress', 'completed', 'failed_permanent', 'failed_transient', 'commit_uncertain', 'expired')),\n  constraint idempotency_response_status_ck\n    check (response_status is null or response_status between 100 and 599),\n  constraint idempotency_response_body_shape_ck\n    check (response_body is null or jsonb_typeof(response_body) in ('object', 'array')),\n  constraint idempotency_response_headers_shape_ck\n    check (jsonb_typeof(response_headers) = 'object'),\n  constraint idempotency_expires_after_created_ck\n    check (expires_at > created_at),\n  constraint idempotency_updated_after_created_ck\n    check (updated_at >= created_at),\n  unique (tenant_id, module, surface, method, route_template, operation_id, idempotency_key)\n);\n\ncreate index idempotency_tenant_expires_idx on platform.idempotency_key(tenant_id, expires_at);\ncreate index idempotency_status_lock_idx on platform.idempotency_key(status, locked_until);\ncreate index idempotency_request_hash_idx on platform.idempotency_key(request_hash);\ncreate unique index case_1edtech_idempotency_key_uidx\n  on platform.idempotency_key(tenant_id, module, surface, idempotency_key)\n  where module = 'case' and surface = '1edtech';",
      "invalidExamples": [
        "Same scope and key with a different request_hash is a 409 idempotency conflict, not a second mutation.",
        "response_body includes raw package bytes, JWTs, headers, IP addresses, user agents, learner PII, or unredacted Problem details.",
        "route_template stores a concrete path like /tenants/0d4.../qti/packages instead of /tenants/{tenant_id}/qti/packages.",
        "expires_at is null or earlier than created_at."
      ],
      "example": {
        "idempotency_key_id": "b81db6f4-c7ea-4757-b5aa-87570f7ad119",
        "tenant_id": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
        "module": "qti",
        "surface": "1edtech",
        "method": "POST",
        "route_template": "/tenants/{tenant_id}/qti/packages",
        "operation_id": "qti.packages.import",
        "idempotency_key": "pkg-upload-2026-05-21-001",
        "request_hash": "sha256:c3def4353e3f07428c94ff3675ed7f0007811dfd7fcbf7044df6c7800f8bd478",
        "canonical_request_hash": "sha256:c3def4353e3f07428c94ff3675ed7f0007811dfd7fcbf7044df6c7800f8bd478",
        "claim_protocol": null,
        "status": "completed",
        "response_status": 201,
        "response_body": {
          "packageId": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
          "importStatus": "imported"
        },
        "response_headers": {},
        "resource_type": "qti.content_package",
        "resource_id": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
        "first_request_id": "req_20260521_0001",
        "lease_token": null,
        "locked_until": null,
        "expires_at": "2026-05-22T12:01:00Z",
        "created_at": "2026-05-21T12:01:00Z",
        "updated_at": "2026-05-21T12:01:08Z"
      },
      "queries": [
        "-- Claim/replay/conflict decision for one retryable QTI POST. Run inside the same transaction before side effects.\n-- The INSERT uses ON CONFLICT DO NOTHING on the seven-column unique scope. If an implementation uses plain INSERT instead,\n-- catch PostgreSQL unique_violation SQLSTATE 23505 for that same constraint, roll back, and run this decision query before work.\n-- If a concurrent uncommitted claim wins the unique race and ON CONFLICT DO NOTHING makes inserted/existing return no row,\n-- roll back and retry this decision query once before doing work; if the retry still returns no row, return 409 idempotency_in_progress.\n-- Branch response mapping:\n--   claimed -> first claimant; perform the mutation and later finalize this row.\n--   stale_lock_reclaimed -> same-hash stale lease was reset; perform the mutation only after the safe-retry precondition is true, then finalize this row.\n--   replay -> return stored response_status/response_body.\n--   conflict -> 409 Problem code idempotency_conflict.\n--   already_in_progress -> 409 Problem code idempotency_in_progress with Retry-After from locked_until.\n--   commit_uncertain -> 500 Problem code idempotency_commit_uncertain; support reconciliation required.\n--   expired -> 409 Problem code idempotency_key_expired.\nwith inserted as (\n  insert into platform.idempotency_key (\n    tenant_id, module, surface, method, route_template, operation_id,\n    idempotency_key, request_hash, first_request_id, locked_until, expires_at\n  )\n  values (\n    $1, $2, $3, $4, $5, $6,\n    $7, $8, $9, now() + interval '30 seconds', now() + interval '24 hours'\n  )\n  on conflict (tenant_id, module, surface, method, route_template, operation_id, idempotency_key)\n  do nothing\n  returning\n    idempotency_key_id, request_hash, status, response_status, response_body,\n    locked_until, 'claimed'::text as branch\n),\nexisting as (\n  select\n    idempotency_key_id, request_hash, status, response_status, response_body,\n    locked_until\n  from platform.idempotency_key\n  where tenant_id = $1\n    and module = $2\n    and surface = $3\n    and method = $4\n    and route_template = $5\n    and operation_id = $6\n    and idempotency_key = $7\n    and not exists (select 1 from inserted)\n  for update\n),\nclassified as (\n  select *,\n    case\n      when request_hash <> $8 then 'conflict'\n      when status = 'commit_uncertain' then 'commit_uncertain'\n      when status in ('completed', 'failed_permanent') then 'replay'\n      when status = 'expired' then 'expired'\n      when status in ('in_progress', 'failed_transient')\n        and (locked_until is null or locked_until <= now()) then 'stale_lock_reclaimed'\n      else 'already_in_progress'\n    end as branch\n  from existing\n),\nstale_reclaim as (\n  update platform.idempotency_key target\n  set status = 'in_progress',\n      locked_until = now() + interval '30 seconds',\n      updated_at = now()\n  from classified\n  where target.idempotency_key_id = classified.idempotency_key_id\n    and classified.branch = 'stale_lock_reclaimed'\n  returning\n    target.idempotency_key_id, target.request_hash, target.status,\n    target.response_status, target.response_body, target.locked_until,\n    'stale_lock_reclaimed'::text as branch\n),\ndecision as (\n  select * from inserted\n  union all\n  select * from stale_reclaim\n  union all\n  select\n    idempotency_key_id, request_hash, status, response_status, response_body,\n    locked_until, branch\n  from classified\n  where branch <> 'stale_lock_reclaimed'\n)\nselect\n  idempotency_key_id,\n  branch as idempotency_decision,\n  case\n    when branch = 'replay' then response_status\n    when branch = 'commit_uncertain' then 500\n    when branch in ('conflict', 'already_in_progress', 'expired') then 409\n    else null\n  end as replay_or_problem_status,\n  case when branch = 'replay' then response_body else null end as replay_body,\n  case\n    when branch = 'conflict' then 'idempotency_conflict'\n    when branch = 'already_in_progress' then 'idempotency_in_progress'\n    when branch = 'commit_uncertain' then 'idempotency_commit_uncertain'\n    when branch = 'expired' then 'idempotency_key_expired'\n    else null\n  end as problem_code\nfrom decision;",
        "update platform.idempotency_key set status = 'completed', response_status = $2, response_body = $3, resource_type = $4, resource_id = $5, locked_until = null, updated_at = now() where idempotency_key_id = $1 and status = 'in_progress';",
        "update platform.idempotency_key set status = 'failed_permanent', response_status = $2, response_body = $3, locked_until = null, updated_at = now() where idempotency_key_id = $1 and status = 'in_progress';",
        "update platform.idempotency_key set status = 'failed_transient', response_status = null, response_body = null, locked_until = null, updated_at = now() where idempotency_key_id = $1 and status = 'in_progress';",
        "update platform.idempotency_key set status = 'commit_uncertain', response_status = null, response_body = null, locked_until = null, updated_at = now() where idempotency_key_id = $1 and status = 'in_progress';"
      ],
      "referenceCards": [
        {
          "title": "Request hash canonicalization",
          "summary": "By default, request_hash is the SHA-256 digest of an RFC 8785 / JSON Canonicalization Scheme (JCS) component array, not a digest of raw request bytes and not a free-form implementation choice. An exact route profile in this Platform-owned dictionary may define a different compatibility-preserving canonical input.",
          "rules": [
            "Default component order is fixed: [\"v1\", METHOD, route_template, tenant_id, module, surface, operation_id, canonical_payload_sha256, canonical_header_sha256].",
            "METHOD is uppercase; route_template is the documented template with variables in braces; tenant_id, module, surface, and operation_id are the exact values stored in the unique idempotency scope.",
            "For JSON request bodies, canonical_payload_sha256 is the SHA-256 of RFC 8785 / JCS canonical JSON: reject duplicate object keys, accept only I-JSON values, sort object keys lexicographically at every object level, preserve array order, preserve strings as-is with no Unicode normalization, emit no insignificant whitespace, serialize primitives and finite numbers per JCS, and UTF-8 encode the result.",
            "For non-JSON uploads, canonical_payload_sha256 is the endpoint-documented streaming SHA-256 of the bytes or package digest; the raw body is never stored in platform.idempotency_key.",
            "canonical_header_sha256 is the SHA-256 of RFC 8785 / JCS canonical JSON containing only lowercase header names the endpoint declares idempotency-relevant. When no headers are relevant, hash an empty object, not the full request header set.",
            "Under the default profile, the stored value is \"sha256:\" plus the lowercase hex digest of the RFC 8785 / JCS canonical JSON component array.",
            "A route-specific hash profile may differ only when this Platform-owned dictionary names the exact route, canonical fields, compatibility reason, and conflict rule. Implementation-only hash exceptions are invalid."
          ],
          "example": {
            "requestBody": {
              "packageUrl": "s3://loop-artifacts/demo/qti-package.zip",
              "profile": "qti3",
              "dryRun": false
            },
            "canonicalPayloadJson": "{\"dryRun\":false,\"packageUrl\":\"s3://loop-artifacts/demo/qti-package.zip\",\"profile\":\"qti3\"}",
            "canonicalPayloadSha256": "sha256:e0d1774a456d4048632d5de17b291cfaef674580b79bd385648333e4fa401116",
            "canonicalHeadersJson": "{\"content-type\":\"application/json\"}",
            "canonicalHeaderSha256": "sha256:940a617179f48cedaf9e31fe07bb583861ebee3edf13e258621a715110e3e31d",
            "componentArrayJson": "[\"v1\",\"POST\",\"/tenants/{tenant_id}/qti/packages\",\"0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3\",\"qti\",\"1edtech\",\"qti.packages.import\",\"sha256:e0d1774a456d4048632d5de17b291cfaef674580b79bd385648333e4fa401116\",\"sha256:940a617179f48cedaf9e31fe07bb583861ebee3edf13e258621a715110e3e31d\"]",
            "requestHash": "sha256:c3def4353e3f07428c94ff3675ed7f0007811dfd7fcbf7044df6c7800f8bd478"
          },
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 pins same-hash replay and different-hash conflict; PITD-014 requires the data dictionary to carry the exact field contract.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          }
        },
        {
          "title": "Claim/replay/conflict middleware responses",
          "summary": "The claim query below returns one branch, and shared-default middleware maps that branch to exactly one response behavior before any side effects run. An exact Platform-owned route profile may override the transport mapping or choose a more conservative non-reclaimable outcome while preserving the same no-side-effect branch discipline.",
          "branches": [
            {
              "branch": "claimed",
              "condition": "No existing row is visible in the full unique scope, so this request is the first claimant.",
              "middlewareResponse": "Proceed with the mutation inside the same transaction or operation lease; no HTTP response is sent yet. Finalize the row as completed, failed_permanent, failed_transient, or commit_uncertain according to the outcome rules below."
            },
            {
              "branch": "stale_lock_reclaimed",
              "condition": "An existing row has the same request_hash, status in in_progress or failed_transient, and locked_until is null or no later than now(). The prior worker's lease is stale; the operation is reclaimable only when the mutation is proven not to have committed or is internally idempotent. A different request_hash is still conflict, not reclaim, and commit_uncertain is never reclaimable.",
              "middlewareResponse": "The worker that holds FOR UPDATE on the stale row resets status to in_progress, extends locked_until, updates updated_at, and proceeds only under the safe-retry precondition. Treat this like claimed for side effects after that precondition is true, but preserve the branch name for logs, metrics, and audit explanation."
            },
            {
              "branch": "replay",
              "condition": "Existing row has the same request_hash and status in completed or failed_permanent.",
              "middlewareResponse": "By default, return the stored response_status and response_body exactly as the safe replay for this tenant. An explicit route profile may map the stored result to a different replay transport status. Do not run the mutation again."
            },
            {
              "branch": "conflict",
              "condition": "Existing row has the same unique scope and Idempotency-Key but a different request_hash.",
              "middlewareResponse": "Return 409 RFC 7807 Problem with code idempotency_conflict. Do not run side effects and do not overwrite the first row."
            },
            {
              "branch": "already_in_progress",
              "condition": "Existing row has the same request_hash, status in in_progress or failed_transient, and locked_until is still in the future.",
              "middlewareResponse": "By default, return 409 RFC 7807 Problem with code idempotency_in_progress and Retry-After equal to the remaining lock seconds, clamped to at least 1. An explicit route profile may return a documented progress status instead. Do not run side effects and do not save a replay body for this concurrent request."
            },
            {
              "branch": "concurrent_insert_loser",
              "condition": "This worker tried to insert a new scoped key at the same time as another worker. PostgreSQL either reports unique_violation SQLSTATE 23505 on the seven-column unique constraint or, when the documented ON CONFLICT DO NOTHING form is used, the inserted and existing CTEs return no row because the winning row is still uncommitted.",
              "middlewareResponse": "Roll back the decision transaction immediately, wait for the winning transaction to become visible, and rerun this same decision query once before doing any side effects. The second decision must then resolve to replay, conflict, already_in_progress, expired, commit_uncertain, stale_lock_reclaimed, or claimed. If it still returns no row, return 409 idempotency_in_progress with Retry-After: 1 rather than running the mutation."
            },
            {
              "branch": "commit_uncertain",
              "condition": "Existing row has the same request_hash and status commit_uncertain, meaning a prior worker could not prove whether platform-owned side effects committed and did not store a safe replay body.",
              "middlewareResponse": "Return 500 RFC 7807 Problem with code idempotency_commit_uncertain, include requestId and traceId for support, and do not run side effects. Only module-specific reconciliation may later move the row to completed with a replay body or another documented non-retryable final state."
            },
            {
              "branch": "expired",
              "condition": "Existing row is expired inside the retained audit window.",
              "middlewareResponse": "Return 409 RFC 7807 Problem with code idempotency_key_expired. The client must choose a new Idempotency-Key if it wants a new operation."
            }
          ],
          "problemExample": {
            "type": "https://platform.timeback.com/problems/idempotency-in-progress",
            "title": "Idempotency key is already processing",
            "status": 409,
            "code": "idempotency_in_progress",
            "detail": "The original request for this Idempotency-Key is still running. Retry the same request after the Retry-After interval.",
            "requestId": "req_20260521_0002",
            "traceId": "trace_20260521_0002"
          },
          "responseHeaders": {
            "Retry-After": "17"
          },
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 defines typed Problem errors; PITD-007 defines in-progress conflict behavior before duplicate side effects.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          }
        },
        {
          "title": "Live-lock and stale-lock-reclaim rules",
          "summary": "locked_until is a short operation lease, not a queue, not a background-job timer, and not a hint clients interpret themselves. These are the shared defaults; an exact Platform-owned route profile may define a documented progress response or a more conservative terminal stale outcome without allowing duplicate execution.",
          "rules": [
            "Concurrent live-lock rule (default): when a same-scope, same-hash row is status in_progress or failed_transient and locked_until is greater than now(), middleware returns 409 idempotency_in_progress with Retry-After. It never waits inside the database transaction, never performs side effects, and never writes a replay body for the second request.",
            "Stale-lock-reclaim rule (default): when a same-scope, same-hash row is status in_progress or failed_transient and locked_until is null or no later than now(), exactly one worker may lock that row with FOR UPDATE, set status='in_progress', set locked_until=now()+interval '30 seconds', set updated_at=now(), and continue under branch stale_lock_reclaimed only if the mutation is proven not to have committed or the operation is internally idempotent.",
            "Reclaim is same-hash only. A same Idempotency-Key with a different request_hash returns idempotency_conflict even if locked_until is stale, because key reuse with different content is never allowed to reclaim a row.",
            "Commit-uncertain rule: if a worker cannot prove whether platform-owned side effects committed and cannot reconstruct a safe replay body, it must set status='commit_uncertain' with null response_status, null response_body, and null locked_until. Later retries return idempotency_commit_uncertain and never stale-lock-reclaim that row.",
            "Long-running asynchronous work should finalize the idempotency row with a replayable 202 response and move progress into a job/resource table. It must not keep extending locked_until for the entire background job.",
            "The index (status, locked_until) exists for stale-lock-reclaim and cleanup scans such as where status in ('in_progress','failed_transient') and locked_until <= now(). It is not a customer search index."
          ],
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 requires one platform-owned concurrency contract for idempotent writes; the data dictionary must explain the lock branch and the status/locked_until index without source-code inspection.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          }
        },
        {
          "title": "CASE 1EdTech transactional idempotency profile",
          "summary": "Platform-owned route profile for every retryable CASE 1.1 write. It makes the customer Idempotency-Key tenant-wide within CASE 1EdTech and commits each business mutation with its terminal replay receipt.",
          "rules": [
            "Scope is exactly tenant_id plus module=case, surface=1edtech, and idempotency_key, enforced by partial unique index case_1edtech_idempotency_key_uidx. Method, route_template, and operation_id remain required ledger identity, but reusing a key for another CASE route conflicts instead of creating a second scope.",
            "request_hash is sha256:<lowercase hex> over recursively key-sorted JSON with fields version=case-v2, method, routeTemplate, operationId, tenantId, and requestBody. POST requestBody is the submitted JSON; PUT/PATCH requestBody also includes the concrete resourceId and If-Match; DELETE includes resourceId, body=null, and If-Match; CFPackage import uses the submitted package JSON. Object keys sort at every depth, array order and string bytes are preserved, and JSON primitives use JSON serialization.",
            "A short claim transaction inserts status=in_progress, canonical_request_hash=request_hash, claim_protocol=case-v2, a server-generated case-v2:<uuid> lease_token, the route/method/operation identity, and a 30-second locked_until before validation or business side effects. first_request_id is audit identity, never ownership.",
            "A same-hash live contender returns the existing CASE 409 case:idempotency_conflict Problem contract with Retry-After clamped to 1-30 seconds. A different hash returns the same 409 code before its callback. Neither contender waits behind or executes the mutation.",
            "The elected owner locks the exact tenant/key/hash/protocol/token row, performs the CASE mutation through the same PostgreSQL transaction, writes status=completed plus response status/body/headers and resource identity, then commits once. POST, PUT, PATCH, DELETE, Alignment writes, and CFPackage imports all use this transaction-bound repository path.",
            "Only an exact stale case-v2 in_progress or failed_transient row with matching hash/token and no response/header/resource evidence may be reclaimed. The conditional takeover has a 250 ms PostgreSQL lock timeout: a still-running owner keeps its row lock and the contender returns in-progress. Unknown protocols, incomplete terminal receipts, and commit_uncertain never execute.",
            "An ambiguous COMMIT is read back. A terminal receipt replays; otherwise the exact owner token may mark commit_uncertain, which is never reclaimed. Failures proven to have rolled back all business writes may become failed_transient. Permanent 4xx Problems are retained as failed_permanent receipts.",
            "The pre-#1454 table case.idempotency_key is a deprecated migration source only. Its completed rows migrate as case-v1-terminal history; current CASE code reads and writes platform.idempotency_key exclusively. The lifecycle and rollout boundary are owned by loop/context/case-idempotency-claim-decision.md."
          ],
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-024 and CASE CITD-008 require a shared durable claim, exact replay metadata, and fail-closed ambiguous outcomes; Issue #1454 defines the CASE route profile.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          }
        },
        {
          "title": "Content Alpha QTI transactional idempotency profile",
          "summary": "Platform-owned route profile for POST /tenants/{tenantId}/alpha/content/imports/qti-package. It preserves the deployed Content Alpha retry contract while keeping the shared ledger lifecycle and no-duplicate guarantee authoritative here.",
          "rules": [
            "Scope is exactly module=content, surface=alpha, method=POST, route_template=/tenants/{tenantId}/alpha/content/imports/qti-package, and operation_id=content.import_qti_package. No other route inherits this profile implicitly.",
            "For this route only, request_hash is sha256:<lowercase hex> over canonical JSON with keys package_hash, byte_length, and sourceName. package_hash is the SHA-256 of the exact ZIP bytes, byte_length is the exact byte count, and sourceName is the exact X-QTI-Source-Name value when present, otherwise the exact legacy X-Content-Source-Name value when present, otherwise null. X-QTI-Source-Name takes precedence when both headers are present. This compact profile and legacy-header fallback are retained for deployed-ledger compatibility; same-length changed bytes still conflict because package_hash changes.",
            "A caller generates a candidate idempotency_key_id UUID before INSERT. The unique-scope upsert may return the winning row to every contender, but only the caller whose candidate equals the returned primary key owns the claim and may execute. first_request_id remains the audit request id and is not an ownership token.",
            "Only the winning claimant may perform prerequisite seed repair. QTI Content writes and the final status=completed ledger update, response_status=202, redacted response_body, response headers, resource type, and resource id commit in one bound PostgreSQL transaction. response_status and response_body remain null while status is in_progress.",
            "A live same-hash retry returns 202 application/json with status=in_progress and Retry-After, without storing that progress body or performing side effects. This is the explicit route exception to the shared default 409 idempotency_in_progress mapping.",
            "The implementation must preserve database read/claim capacity while long import transactions are open so same-instance retries can observe the committed claim and return the live 202 promptly. Capping long transactions at poolMax-1 is a conforming mechanism; queued imports must wait outside the connection pool.",
            "A completed same-request retry returns HTTP 200 with Idempotency-Replayed: true and the stored response body and resource identifiers. The stored first-attempt response_status remains 202. This is the explicit route transport exception to exact stored-status replay; the body itself must remain equivalent after delivery-URL canonicalization.",
            "An expired unfinished claim returns terminal 503 and is never automatically reclaimed or rerun. This conservative route exception applies because the synchronous importer has no independent job/resource state that proves a stale owner stopped; operators must reconcile explicitly rather than rotate keys automatically.",
            "A completed legacy row may bypass request_hash equality only when its stored public response proves the exact same package_hash, byte_length, and source_name, or when it matches the immediately preceding full-parser request hash exactly. Active, failed, expired, or commit_uncertain rows never use legacy equivalence.",
            "A different package hash, byte length, or source name under the same key returns 409 idempotency_conflict. Recovery must never scan Content rows by source name, title, creation time, or other heuristic identity."
          ],
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 owns ledger replay/conflict semantics; this explicit profile governs Content Alpha issue #613/#616 without creating a Content-local semantic fork.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          }
        },
        {
          "title": "Worked QTI POST middleware flow",
          "summary": "For a retryable QTI package import, middleware runs the decision query first, branches before side effects, and finalizes the same ledger row only after the branch is known.",
          "rules": [
            "Step 1: derive the unique scope exactly as tenant_id=0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3, module=qti, surface=1edtech, method=POST, route_template=/tenants/{tenant_id}/qti/packages, operation_id=qti.packages.import, idempotency_key=pkg-upload-2026-05-21-001.",
            "Step 2: derive request_hash from the canonical component array shown in the request-hash card; the worked QTI POST stores sha256:c3def4353e3f07428c94ff3675ed7f0007811dfd7fcbf7044df6c7800f8bd478.",
            "Step 3: run the claim/replay/conflict decision query. Its INSERT uses ON CONFLICT DO NOTHING, then locks any existing row with FOR UPDATE so every retry follows the same branch table. If an implementation uses a plain INSERT instead, catch PostgreSQL unique_violation SQLSTATE 23505 for this unique constraint, roll back, and rerun the same decision query before side effects.",
            "Step 4: if the branch is claimed or stale_lock_reclaimed, run the QTI import once. For stale_lock_reclaimed, first prove the prior mutation did not commit or that the import is internally idempotent under the same request_hash. On success, run the completed finalizer update with the idempotency_key_id returned by the decision query, response_status=201, the redacted replay body, resource_type=qti.content_package, and the created package id.",
            "Step 5: if the decision query returns no row because ON CONFLICT DO NOTHING lost to a concurrent uncommitted insert, roll back the decision transaction, wait for the winning transaction to become visible, rerun the decision query once, and do not run the QTI import unless the rerun returns claimed or stale_lock_reclaimed.",
            "Step 6: if the same request returns replay later, return the stored response_status and response_body. If a retry reuses the same key with a different request_hash, return idempotency_conflict. If the first worker is still locked, return 409 idempotency_in_progress with Retry-After.",
            "Step 7: if validation or authorization fails before side effects, run the failed_permanent finalizer with the safe Problem response. Use failed_transient only when the failed attempt is proven not to have committed platform-owned side effects, or when the operation is internally idempotent under the same request_hash. If the worker cannot prove whether side effects committed, run the commit_uncertain finalizer; later same-hash retries return idempotency_commit_uncertain and must not reclaim or rerun the mutation."
          ],
          "example": {
            "firstDecision": {
              "idempotency_decision": "claimed",
              "idempotency_key_id": "b81db6f4-c7ea-4757-b5aa-87570f7ad119",
              "replay_or_problem_status": null
            },
            "staleLockReclaimed": {
              "idempotency_decision": "stale_lock_reclaimed",
              "idempotency_key_id": "b81db6f4-c7ea-4757-b5aa-87570f7ad119",
              "replay_or_problem_status": null,
              "locked_until": "2026-05-21T12:02:00Z"
            },
            "completedFinalizer": {
              "status": "completed",
              "response_status": 201,
              "response_body": {
                "packageId": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
                "importStatus": "imported"
              },
              "resource_type": "qti.content_package",
              "resource_id": "7f2e4dd2-c147-49ea-af77-41a6fdd70980"
            },
            "sameRequestRetry": {
              "idempotency_decision": "replay",
              "replay_or_problem_status": 201,
              "replay_body": {
                "packageId": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
                "importStatus": "imported"
              }
            },
            "sameKeyDifferentBodyRetry": {
              "idempotency_decision": "conflict",
              "replay_or_problem_status": 409,
              "problem_code": "idempotency_conflict"
            }
          },
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 requires same-key same-request replay and same-key different-request conflict; the data dictionary must show the middleware sequence without requiring source-code inspection.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          }
        }
      ],
      "fields": [
        {
          "name": "idempotency_key_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable identifier for the retry ledger row. Audit rows refer to this value rather than repeating replay internals.",
          "constraints": "Must be a valid PostgreSQL UUID and unique as the primary key.",
          "allowedValues": null,
          "relationship": "Referenced by platform.audit_log.idempotency_key_id. One idempotency row can explain many audit rows for retries and final outcomes.",
          "example": "b81db6f4-c7ea-4757-b5aa-87570f7ad119",
          "invalidWhen": "Not a UUID, reused across rows, or exposed as the customer Idempotency-Key header value.",
          "edgeCases": "This is an internal row id; the externally supplied key is idempotency_key.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 requires a shared retry ledger.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-idempotency-key-id"
        },
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Tenant that owns the retry scope and the mutation being protected.",
          "constraints": "Must reference platform.tenant(tenant_id).",
          "allowedValues": null,
          "relationship": "Many idempotency rows belong to one platform.tenant.",
          "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
          "invalidWhen": "Null, not found in platform.tenant, or different from the tenant_id claim in the Bearer JWT for a tenant-scoped route.",
          "edgeCases": "Platform-wide maintenance operations that do not have a tenant must not use this table unless the operation is deliberately scoped to a tenant row.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 defines tenant_id as part of idempotency scope.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-tenant-id"
        },
        {
          "name": "module",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Scope key",
          "meaning": "Module namespace whose operation claimed the idempotency key.",
          "constraints": "Must satisfy module_key_allowed: platform, incept, qti, oneroster, caliper, case, nweamap, ed_fi, people_and_orgs, curriculum, content, events, results, analytics.",
          "allowedValues": "module_key",
          "relationship": "Pairs with surface, route_template, and operation_id to define replay scope.",
          "example": "qti",
          "invalidWhen": "Null, outside module_key, used to store a route group instead of the module namespace, or used by /platform/modules as a release-status substitute.",
          "edgeCases": "module=qti remains valid identity for QTI-owned retry scopes independent of release-state display. Public registries must separately expose module_release_status derived from loop/qti/state.json; at this generation, qti/1edtech is approved because all required QTI 1EdTech deliverables are approved.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-002 requires module schemas and shared platform operational tables.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-002-module-schema-boundaries"
          },
          "anchor": "field-platform-idempotency-key-module"
        },
        {
          "name": "surface",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Scope key",
          "meaning": "Surface whose API contract produced the retryable operation.",
          "constraints": "Must satisfy surface_code_allowed: platform, 1edtech, or alpha.",
          "allowedValues": "surface_code",
          "relationship": "Pairs with module so qti/1edtech and qti/alpha operations can have different customer contracts over shared persistence.",
          "example": "1edtech",
          "invalidWhen": "Null, outside surface_code, or used to hide whether an Alpha divergence changed operation behavior.",
          "edgeCases": "The platform surface uses module=platform and surface=platform.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-015 defines platform, 1EdTech, and Alpha surfaces.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-015-surface-model-and-derivation"
          },
          "anchor": "field-platform-idempotency-key-surface"
        },
        {
          "name": "method",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Scope key",
          "meaning": "HTTP method for the mutation protected by the key.",
          "constraints": "Must satisfy mutation_http_method_allowed: POST, PUT, PATCH, or DELETE.",
          "allowedValues": "mutation_http_method",
          "relationship": "Part of the unique retry scope. Same route and key under different mutation methods are distinct scopes.",
          "example": "POST",
          "invalidWhen": "Null, GET, lowercase if the implementation normalizes to uppercase, or method does not match the documented endpoint.",
          "edgeCases": "PUT/PATCH operations that can overwrite user work still need If-Match or an equivalent validator; idempotency does not replace optimistic concurrency.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 defines retryable create, upload, import, export-job, and command operations.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-method"
        },
        {
          "name": "route_template",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Scope key",
          "meaning": "Stable route pattern from the customer website or OpenAPI operation, with variable path segments expressed as braces.",
          "constraints": "Must start with /. Must not contain a query string. Path variables use {name}. Must not include concrete tenant IDs, resource IDs, learner refs, or secrets.",
          "allowedValues": null,
          "relationship": "Part of the unique retry scope; links the row back to a documented endpoint.",
          "example": "/tenants/{tenant_id}/qti/packages",
          "invalidWhen": "Contains concrete UUIDs, query strings, raw learner refs, access tokens, or an undocumented internal route.",
          "edgeCases": "If the Alpha route names the tenant as workspaceId, the template still uses the public Alpha route name documented by that surface.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 requires endpoint-local contracts and PITD-007 requires route template scope.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-route-template"
        },
        {
          "name": "operation_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Scope key",
          "meaning": "Stable operation identifier used by docs, OpenAPI, logs, audit, and idempotency middleware.",
          "constraints": "1 to 120 characters. Lowercase letters, digits, dots, underscores, and hyphens. Must be stable across wording-only documentation edits.",
          "allowedValues": null,
          "relationship": "Part of the unique retry scope and repeated in audit rows.",
          "example": "qti.packages.import",
          "invalidWhen": "Blank, generated from a localized title, contains spaces, or changes without a customer-site and implementation update.",
          "edgeCases": "If two routes intentionally share replay behavior, they still need separate operation_id values unless the architecture explicitly declares them equivalent.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-010 and PITD-009 require shared operation_id fields.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-010-observability-and-slos"
          },
          "anchor": "field-platform-idempotency-key-operation-id"
        },
        {
          "name": "idempotency_key",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Scope key",
          "meaning": "Opaque customer-supplied Idempotency-Key header value for one retryable operation.",
          "constraints": "1 to 128 printable ASCII characters after trimming. Unique within the tenant/module/surface/method/route_template/operation_id scope. Must not be a token, password, email, phone number, student identifier, or raw request hash.",
          "allowedValues": null,
          "relationship": "Part of the unique retry scope. Not a foreign key.",
          "example": "pkg-upload-2026-05-21-001",
          "invalidWhen": "Blank, reused for different request_hash in the same scope, contains credentials or direct learner PII, or exceeds the documented length.",
          "edgeCases": "Same key with same request_hash replays; same key with different request_hash returns 409.",
          "provenance": {
            "label": "Platform shared",
            "basis": "QTI package ingest used Idempotency-Key; PITD-007 promotes the rule.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-idempotency-key"
        },
        {
          "name": "request_hash",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Digest of the canonical replay identity for the first request. It lets middleware distinguish a safe retry from key reuse with different content.",
          "constraints": "Must be sha256:<64 lowercase hex characters>. The default hash input order is [\"v1\", METHOD, route_template, tenant_id, module, surface, operation_id, canonical_payload_sha256, canonical_header_sha256]. For JSON bodies, canonical_payload_sha256 uses RFC 8785 / JCS canonical JSON: reject duplicate object keys, accept only I-JSON values, sort object keys lexicographically at every object level, preserve array order, preserve strings as-is with no Unicode normalization, emit no insignificant whitespace, serialize primitives and finite numbers per JCS, and UTF-8 encode. For non-JSON uploads, use the endpoint-documented streaming byte/package digest. canonical_header_sha256 hashes RFC 8785 / JCS canonical JSON of only endpoint-declared idempotency-relevant lowercase headers, or {} when none apply. A different canonical input is valid only for a route explicitly named by a Platform-owned reference card, such as the Content Alpha QTI transactional profile.",
          "allowedValues": null,
          "relationship": "No foreign key. Compared with later requests in the same unique scope.",
          "example": "sha256:c3def4353e3f07428c94ff3675ed7f0007811dfd7fcbf7044df6c7800f8bd478",
          "invalidWhen": "Missing algorithm prefix, not sha256, uppercase/malformed hex, computed from raw bytes or non-JCS JSON, contains duplicate object keys or non-I-JSON values, or includes raw secrets in a way that would be logged.",
          "edgeCases": "Large uploads hash normalized bytes or a precomputed payload hash, never raw bytes stored in this table. The worked example in the object reference card is the default canonical QTI POST import hash for the example row. The Content Alpha QTI profile pins its compact package_hash/byte_length/sourceName identity for deployed-ledger compatibility.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 requires request hash conflict detection.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-request-hash"
        },
        {
          "name": "canonical_request_hash",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Immutable canonical request identity retained when claim_protocol needs request_hash as a rolling-deployment or active-owner fence.",
          "constraints": "Nullable for protocols that store the canonical sha256 hash directly in request_hash. When present, must be sha256:<64 lowercase hex characters> and must not change for the row's lifetime.",
          "allowedValues": null,
          "relationship": "No foreign key. Protocol-specific claim and completion predicates compare it with the incoming canonical identity.",
          "example": "sha256:c3def4353e3f07428c94ff3675ed7f0007811dfd7fcbf7044df6c7800f8bd478",
          "invalidWhen": "Malformed, changed during completion, derived from a different payload than request_hash, or used to bypass a different-hash conflict.",
          "edgeCases": "CASE case-v2 always sets this equal to its canonical request_hash. Curriculum may temporarily tag request_hash during its legacy bridge while this field retains the canonical value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-024 and module rolling-deployment decisions require immutable request identity across ownership protocols.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-canonical-request-hash"
        },
        {
          "name": "claim_protocol",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Versioned ownership protocol that defines which token, stale-state, finalization, and rolling-deployment rules govern the row.",
          "constraints": "Nullable only for documented legacy/default rows. Current CASE 1EdTech claims use case-v2; a module must have a Platform-owned profile before introducing another value.",
          "allowedValues": null,
          "relationship": "No foreign key. Interpreted together with canonical_request_hash, lease_token, status, locked_until, and the module/surface profile.",
          "example": "case-v2",
          "invalidWhen": "An undocumented free-form value, changed by a contender, or treated as sufficient ownership without the exact tenant/key/hash/token fence.",
          "edgeCases": "Unknown protocols fail closed. Historical CASE rows use case-v1-terminal and are replay-only, never stale-reclaimed.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-024 requires explicit durable ownership and stale/uncertain-state policy.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-claim-protocol"
        },
        {
          "name": "status",
          "type": "text",
          "required": true,
          "default": "'in_progress'",
          "key": null,
          "meaning": "Replay lifecycle state of the idempotency row.",
          "constraints": "Must satisfy idempotency_status_allowed.",
          "allowedValues": "idempotency_status",
          "relationship": "No foreign key. Determines whether middleware replays, rejects, waits, or allows stale-lock reclaim.",
          "example": "completed",
          "invalidWhen": "Outside idempotency_status, null, or incompatible with response_status/locked_until, such as completed with no final status.",
          "edgeCases": "failed_transient and stale in_progress rows can be reclaimed after locked_until only when request_hash matches and the mutation is proven not to have committed or is internally idempotent. commit_uncertain rows are non-reclaimable and return idempotency_commit_uncertain. failed_permanent rows replay the safe Problem response. By default, a matching in_progress row whose locked_until is still in the future returns 409 idempotency_in_progress with Retry-After; middleware must not run the mutation again. The explicit Content Alpha QTI profile instead returns live 202 and terminal stale 503 without rerunning.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 requires original outcome replay and conflict behavior.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-status"
        },
        {
          "name": "response_status",
          "type": "integer",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "HTTP status originally returned for a final replayable outcome.",
          "constraints": "Nullable while in_progress, failed_transient, or commit_uncertain. When present, must be an integer from 100 through 599 and match the stored response_body/resource outcome.",
          "allowedValues": null,
          "relationship": "No foreign key. Used with response_body to replay the original result.",
          "example": "201",
          "invalidWhen": "Present while status is in_progress, outside 100-599, or does not match the Problem/status or resource creation outcome.",
          "edgeCases": "204 outcomes store response_status=204 and response_body=null.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 defines HTTP status policy and PITD-007 defines replay.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-006-http-envelope-and-errors"
          },
          "anchor": "field-platform-idempotency-key-response-status"
        },
        {
          "name": "response_body",
          "type": "jsonb",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Redacted JSON body safe to replay to the same tenant for completed or failed_permanent outcomes.",
          "constraints": "Nullable. When present, must be a JSON object or array that matches the documented response schema. Must not include secrets, raw package bytes, headers, access tokens, IP addresses, user agents, direct learner PII, or unredacted processing traces.",
          "allowedValues": null,
          "relationship": "May contain resource identifiers that point into module tables, but the module table remains source of record.",
          "example": "{\"packageId\":\"7f2e4dd2-c147-49ea-af77-41a6fdd70980\",\"importStatus\":\"imported\"}",
          "invalidWhen": "Stores raw request body, file bytes, secrets, PII, non-JSON text, or a body that cannot be returned to the authenticated tenant.",
          "edgeCases": "For async operations, response_body can be a 202 job resource even though final module processing continues elsewhere.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 requires redacted Problem/errors; PITD-007 requires replayable outcomes.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-response-body"
        },
        {
          "name": "response_headers",
          "type": "jsonb",
          "required": true,
          "default": "'{}'::jsonb",
          "key": null,
          "meaning": "Redacted terminal response headers needed to replay the original HTTP contract, including ETag and documented retry metadata.",
          "constraints": "Must be a JSON object. Values must be safe for the same authenticated tenant and must exclude credentials, cookies, tracing internals, IP addresses, and user agents.",
          "allowedValues": null,
          "relationship": "No foreign key. Replayed with response_status and response_body for completed or failed_permanent rows.",
          "example": "{\"etag\":\"\\\"case-v1\\\"\"}",
          "invalidWhen": "An array/scalar, contains authorization or set-cookie, or omits an ETag that the original CASE mutation returned.",
          "edgeCases": "Empty object is valid. A 204 response keeps response_body SQL null while headers remain an object.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 requires exact endpoint-local HTTP contracts and PITD-024 requires persisted replay metadata.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-006-http-envelope-and-errors"
          },
          "anchor": "field-platform-idempotency-key-response-headers"
        },
        {
          "name": "resource_type",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Optional type of resource created, imported, deleted, or accepted by the operation.",
          "constraints": "Nullable. When present, use a stable table or API object path such as qti.content_package, qti.delivery_session, platform.tenant, or alpha.activity.",
          "allowedValues": null,
          "relationship": "Pairs with resource_id for audit and support lookup. Does not enforce a foreign key because target tables vary by module.",
          "example": "qti.content_package",
          "invalidWhen": "Contains a display title, localized wording, raw URL, or path with tenant/resource IDs.",
          "edgeCases": "For operations that create multiple resources, store the primary customer-visible resource and put redacted counts in response_body or audit metadata.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 uses resource_type in audit and replay support.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-idempotency-key-resource-type"
        },
        {
          "name": "resource_id",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Optional identifier of the primary resource associated with the replayable outcome.",
          "constraints": "Nullable. When present, must be the canonical resource identifier for resource_type and tenant_id.",
          "allowedValues": null,
          "relationship": "Pairs with resource_type; target cardinality is many idempotency rows may point at one resource only when retries or aliases are documented.",
          "example": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
          "invalidWhen": "Contains a student name, email, phone number, raw package path, or ID outside the tenant.",
          "edgeCases": "Async accepted work can use a job/run id here while the final content resource appears later in module tables.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 requires resource identifiers for operational traceability.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-idempotency-key-resource-id"
        },
        {
          "name": "first_request_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Request identifier of the first request that claimed this key.",
          "constraints": "Required non-empty text, 1 to 120 characters. Must be safe for logs and customer support. Must not contain tokens, IP addresses, user agents, or PII.",
          "allowedValues": null,
          "relationship": "Should match platform.audit_log.request_id for the original attempt when that attempt is audited.",
          "example": "req_20260521_0001",
          "invalidWhen": "Null, blank, regenerated on replay, or includes sensitive request details.",
          "edgeCases": "Retry requests have their own request_id in access logs, but this field stays fixed to the first attempt.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-010 requires request_id in structured operational evidence.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-010-observability-and-slos"
          },
          "anchor": "field-platform-idempotency-key-first-request-id"
        },
        {
          "name": "lease_token",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Server-generated claimant fence used by versioned protocols to prove which request may mutate or finalize the ledger row.",
          "constraints": "Nullable for legacy/default protocols. Current owners must use a cryptographically unpredictable protocol-prefixed token and every takeover/finalizer must compare it conditionally.",
          "allowedValues": null,
          "relationship": "No foreign key. first_request_id remains support/audit identity and is never substituted for this ownership token.",
          "example": "case-v2:3c64bc41-b033-4aad-8c19-a4dfadad13d5",
          "invalidWhen": "Customer supplied, reused across claims, logged as a credential, or omitted from an ownership-sensitive finalizer predicate.",
          "edgeCases": "A safe stale takeover replaces the old token atomically. A superseded owner cannot finalize or mark the row uncertain.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-024 and CASE CITD-008 require durable single-owner fencing before mutation.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-lease-token"
        },
        {
          "name": "locked_until",
          "type": "timestamptz",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Temporary lock deadline used while an in-progress operation is executing.",
          "constraints": "Nullable. When status is in_progress, should be a future timestamp. Must be null for completed, failed_permanent, and commit_uncertain rows.",
          "allowedValues": null,
          "relationship": "No foreign key. Used by middleware to decide whether another worker must reject a concurrent live lock or may reclaim a stale same-hash row.",
          "example": "2026-05-21T12:01:30Z",
          "invalidWhen": "Expired while status remains in_progress without stale-lock-reclaim logic, set on completed rows, or earlier than created_at.",
          "edgeCases": "Long-running async jobs should complete the idempotency row with a 202 response rather than hold this lock for the whole job. By default, a concurrent same-hash request while locked_until is in the future returns 409 idempotency_in_progress and Retry-After from this timestamp; a stale same-hash row may be reset by exactly one FOR UPDATE worker under branch stale_lock_reclaimed only when the safe-retry precondition is true. commit_uncertain rows keep locked_until null and are never stale-lock-reclaimed. The Content Alpha QTI profile documents its live 202 and terminal stale 503 exceptions.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 centralizes replay and conflict behavior.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-locked-until"
        },
        {
          "name": "expires_at",
          "type": "timestamptz",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Timestamp after which the key is no longer promised to replay the original response.",
          "constraints": "Required timestamp with time zone. Must be later than created_at. Default policy is at least 24 hours after first claim; modules may document longer windows for async jobs or exports.",
          "allowedValues": null,
          "relationship": "Indexed for cleanup and expiry marking.",
          "example": "2026-05-22T12:01:00Z",
          "invalidWhen": "Null, before created_at, shorter than the customer website promises, or extended without retention/audit reason.",
          "edgeCases": "Expired rows may remain queryable for audit but must not silently replay after the documented window.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 requires a shared idempotency policy rather than per-module drift.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
          },
          "anchor": "field-platform-idempotency-key-expires-at"
        },
        {
          "name": "created_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Timestamp when the first request claimed the idempotency key.",
          "constraints": "Required timestamp with time zone.",
          "allowedValues": null,
          "relationship": "None.",
          "example": "2026-05-21T12:01:00Z",
          "invalidWhen": "Null, changed after insert, or compared without timezone normalization.",
          "edgeCases": "Use created_at plus expires_at for replay-window reporting.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-017 requires lifecycle timestamps.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-017-migrations-and-ddl-discipline"
          },
          "anchor": "field-platform-idempotency-key-created-at"
        },
        {
          "name": "updated_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Timestamp when the row last changed status, replay body, lock, or expiry.",
          "constraints": "Required timestamp with time zone. Must be greater than or equal to created_at.",
          "allowedValues": null,
          "relationship": "None.",
          "example": "2026-05-21T12:01:08Z",
          "invalidWhen": "Null, earlier than created_at, or left unchanged after finalizing the row.",
          "edgeCases": "Retries that merely read/replay do not need to update updated_at unless the implementation records replay counts elsewhere.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-017 requires DDL discipline and auditability.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-017-migrations-and-ddl-discipline"
          },
          "anchor": "field-platform-idempotency-key-updated-at"
        }
      ],
      "anchor": "table-platform-idempotency-key",
      "sqlComments": "comment on table platform.idempotency_key is 'This table records the first request to claim an Idempotency-Key within a precise Platform-owned scope. The default is tenant/module/surface/operation; explicit route profiles such as CASE 1EdTech may enforce a stricter tenant/module/surface/key scope. Later matching requests replay the original safe result, while key reuse with a different canonical request returns 409 before side effects.';\ncomment on column platform.idempotency_key.idempotency_key_id is 'Stable identifier for the retry ledger row. Audit rows refer to this value rather than repeating replay internals.';\ncomment on column platform.idempotency_key.tenant_id is 'Tenant that owns the retry scope and the mutation being protected.';\ncomment on column platform.idempotency_key.module is 'Module namespace whose operation claimed the idempotency key.';\ncomment on column platform.idempotency_key.surface is 'Surface whose API contract produced the retryable operation.';\ncomment on column platform.idempotency_key.method is 'HTTP method for the mutation protected by the key.';\ncomment on column platform.idempotency_key.route_template is 'Stable route pattern from the customer website or OpenAPI operation, with variable path segments expressed as braces.';\ncomment on column platform.idempotency_key.operation_id is 'Stable operation identifier used by docs, OpenAPI, logs, audit, and idempotency middleware.';\ncomment on column platform.idempotency_key.idempotency_key is 'Opaque customer-supplied Idempotency-Key header value for one retryable operation.';\ncomment on column platform.idempotency_key.request_hash is 'Digest of the canonical replay identity for the first request. It lets middleware distinguish a safe retry from key reuse with different content.';\ncomment on column platform.idempotency_key.canonical_request_hash is 'Immutable canonical request identity retained when claim_protocol needs request_hash as a rolling-deployment or active-owner fence.';\ncomment on column platform.idempotency_key.claim_protocol is 'Versioned ownership protocol that defines which token, stale-state, finalization, and rolling-deployment rules govern the row.';\ncomment on column platform.idempotency_key.status is 'Replay lifecycle state of the idempotency row.';\ncomment on column platform.idempotency_key.response_status is 'HTTP status originally returned for a final replayable outcome.';\ncomment on column platform.idempotency_key.response_body is 'Redacted JSON body safe to replay to the same tenant for completed or failed_permanent outcomes.';\ncomment on column platform.idempotency_key.response_headers is 'Redacted terminal response headers needed to replay the original HTTP contract, including ETag and documented retry metadata.';\ncomment on column platform.idempotency_key.resource_type is 'Optional type of resource created, imported, deleted, or accepted by the operation.';\ncomment on column platform.idempotency_key.resource_id is 'Optional identifier of the primary resource associated with the replayable outcome.';\ncomment on column platform.idempotency_key.first_request_id is 'Request identifier of the first request that claimed this key.';\ncomment on column platform.idempotency_key.lease_token is 'Server-generated claimant fence used by versioned protocols to prove which request may mutate or finalize the ledger row.';\ncomment on column platform.idempotency_key.locked_until is 'Temporary lock deadline used while an in-progress operation is executing.';\ncomment on column platform.idempotency_key.expires_at is 'Timestamp after which the key is no longer promised to replay the original response.';\ncomment on column platform.idempotency_key.created_at is 'Timestamp when the first request claimed the idempotency key.';\ncomment on column platform.idempotency_key.updated_at is 'Timestamp when the row last changed status, replay body, lock, or expiry.';"
    },
    {
      "name": "platform.audit_log",
      "title": "Audit log",
      "short": "Append-only cross-module record of high-risk writes, privileged reads, learner-runtime deletion, denied authorization, and trust changes.",
      "purpose": "This table gives support, compliance, release, and future AI agents one durable account of who did what, under which tenant and module, with what result. Module tables remain the source of record for domain state; audit rows are the redacted narrative that explains sensitive platform actions across modules.",
      "lifecycle": "Inserted once by shared audit middleware at the end of a high-risk operation or authorization decision. Rows are append-only: corrections are represented by a later compensating audit row, not by updating or deleting the original. Retention cleanup requires a named maintenance action and its own audit row.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "PITD-009 defines platform.audit_log as the shared append-only operational table.",
      "itds": [
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        },
        {
          "id": "PITD-008",
          "title": "Student Data Privacy And PII Handling",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
        },
        {
          "id": "PITD-010",
          "title": "Observability, Metrics, And SLOs",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-010-observability-and-slos"
        }
      ],
      "qtiReconciliation": "Adds a shared operational table that QTI did not have. QTI import, authoring, delivery deletion, service-role, conformance, and trust-status operations must emit rows here once the platform shared library is integrated.",
      "primaryKey": "audit_log_id",
      "relationships": [
        "Belongs to one platform.tenant.",
        "May reference one platform.idempotency_key row when the audited operation used Idempotency-Key.",
        "Refers to module resources by resource_type and resource_id instead of foreign keys because target tables vary by module.",
        "One request_id or trace_id can appear in multiple audit rows when a command touches multiple resources."
      ],
      "constraints": [
        "Rows are append-only; ordinary application roles cannot update or delete them.",
        "tenant_id must reference platform.tenant. Cross-tenant maintenance writes one row per affected tenant.",
        "module, surface, action, and outcome must use documented allowed values.",
        "redacted_metadata must be a JSON object and must not include raw request bodies, tokens, learner names, emails, phone numbers, package bytes, IP addresses, or user agents.",
        "http_status must be an integer from 100 through 599."
      ],
      "indexes": [
        "primary key (audit_log_id)",
        "index (tenant_id, occurred_at desc)",
        "index (tenant_id, resource_type, resource_id, occurred_at desc)",
        "index (request_id)",
        "index (trace_id)",
        "index (module, surface, operation_id, occurred_at desc)",
        "index (idempotency_key_id)"
      ],
      "ddl": "create table platform.audit_log (\n  audit_log_id uuid primary key default gen_random_uuid(),\n  tenant_id uuid not null references platform.tenant(tenant_id),\n  module text not null,\n  surface text not null,\n  operation_id text not null,\n  actor_subject text not null,\n  actor_roles text[] not null default '{}'::text[],\n  resource_type text not null,\n  resource_id text not null,\n  action text not null,\n  outcome text not null,\n  http_status integer not null,\n  request_id text not null,\n  trace_id text not null,\n  idempotency_key_id uuid references platform.idempotency_key(idempotency_key_id) on delete set null,\n  occurred_at timestamptz not null default now(),\n  redacted_metadata jsonb not null default '{}'::jsonb,\n  constraint audit_module_ck\n    check (module in ('platform', 'incept', 'qti', 'oneroster', 'caliper', 'case', 'nweamap', 'ed_fi', 'people_and_orgs', 'curriculum', 'content', 'events', 'results', 'analytics')),\n  constraint audit_surface_ck\n    check (surface in ('platform', '1edtech', 'alpha')),\n  constraint audit_action_ck\n    check (action in ('create', 'update', 'delete', 'import', 'export', 'read_privileged', 'runtime_delete', 'conformance_change', 'trust_change', 'authz_denied', 'maintenance')),\n  constraint audit_outcome_ck\n    check (outcome in ('accepted', 'succeeded', 'failed_validation', 'failed_authorization', 'failed_conflict', 'failed_not_found', 'failed_server')),\n  constraint audit_http_status_ck\n    check (http_status between 100 and 599),\n  constraint audit_metadata_object_ck\n    check (jsonb_typeof(redacted_metadata) = 'object'),\n  constraint audit_required_text_ck\n    check (\n      length(btrim(operation_id)) > 0 and\n      length(btrim(actor_subject)) > 0 and\n      length(btrim(resource_type)) > 0 and\n      length(btrim(resource_id)) > 0 and\n      length(btrim(request_id)) > 0 and\n      length(btrim(trace_id)) > 0\n    )\n);\n\ncreate index audit_tenant_time_idx on platform.audit_log(tenant_id, occurred_at desc);\ncreate index audit_resource_idx on platform.audit_log(tenant_id, resource_type, resource_id, occurred_at desc);\ncreate index audit_request_idx on platform.audit_log(request_id);\ncreate index audit_trace_idx on platform.audit_log(trace_id);\ncreate index audit_operation_idx on platform.audit_log(module, surface, operation_id, occurred_at desc);\ncreate index audit_idempotency_idx on platform.audit_log(idempotency_key_id);",
      "invalidExamples": [
        "actor_subject = 'teacher@example.org' because actor subjects must be pseudonymous or hashed.",
        "redacted_metadata stores raw QTI package bytes, processing traces with student identity, request headers, IP address, or access token.",
        "A service-role tenant suspension changes platform.tenant.status without an audit row.",
        "action = 'changed' or outcome = 'ok' because allowed values must be behaviorally explained."
      ],
      "example": {
        "audit_log_id": "a597b7de-b1dd-4c9e-93a3-9623cb90bc34",
        "tenant_id": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
        "module": "qti",
        "surface": "1edtech",
        "operation_id": "qti.packages.import",
        "actor_subject": "userhash:1bd7b5bd0d77",
        "actor_roles": [
          "teacher",
          "content-admin"
        ],
        "resource_type": "qti.content_package",
        "resource_id": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
        "action": "import",
        "outcome": "succeeded",
        "http_status": 201,
        "request_id": "req_20260521_0001",
        "trace_id": "trace_20260521_a1f4",
        "idempotency_key_id": "b81db6f4-c7ea-4757-b5aa-87570f7ad119",
        "occurred_at": "2026-05-21T12:01:08Z",
        "redacted_metadata": {
          "packageHash": "sha256:6a8c1f58c16f4b0b4f0a0d8c6be8d226e3d5d80f0b2f7d2f49e6d7d9e9d4f1cb",
          "resourceCount": 18,
          "fileCount": 42
        }
      },
      "queries": [
        "insert into platform.audit_log (tenant_id, module, surface, operation_id, actor_subject, actor_roles, resource_type, resource_id, action, outcome, http_status, request_id, trace_id, idempotency_key_id, redacted_metadata) values ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15);",
        "select occurred_at, actor_subject, action, outcome, http_status from platform.audit_log where tenant_id = $1 and resource_type = $2 and resource_id = $3 order by occurred_at desc;",
        "select module, surface, operation_id, outcome, count(*) from platform.audit_log where tenant_id = $1 and occurred_at >= now() - interval '7 days' group by module, surface, operation_id, outcome order by count(*) desc;"
      ],
      "fields": [
        {
          "name": "audit_log_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable identifier for one append-only audit event.",
          "constraints": "Must be a valid PostgreSQL UUID and unique as the primary key.",
          "allowedValues": null,
          "relationship": "No child table in this dictionary; support tools and future evidence exports may reference it.",
          "example": "a597b7de-b1dd-4c9e-93a3-9623cb90bc34",
          "invalidWhen": "Not a UUID, reused, or generated outside the database without collision safeguards.",
          "edgeCases": "Corrections never update this row; write a later audit event that references the corrected resource.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 required audit_log_id.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-audit-log-id"
        },
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Tenant affected by the audited action.",
          "constraints": "Must reference platform.tenant(tenant_id). Cross-tenant maintenance must emit one row per affected tenant rather than a tenantless row.",
          "allowedValues": null,
          "relationship": "Many audit rows belong to one platform.tenant.",
          "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
          "invalidWhen": "Null, not found, copied from an untrusted path without JWT tenant validation, or used to record a resource outside the tenant.",
          "edgeCases": "Authenticated authorization denials should use the route tenant after checking it is a real platform.tenant row; missing-auth events stay in security logs, not tenant audit rows.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 required tenant_id and PITD-005 requires tenant scope enforcement.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-tenant-id"
        },
        {
          "name": "module",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Audit dimension",
          "meaning": "Module responsible for the operation being audited.",
          "constraints": "Must satisfy module_key_allowed: platform, incept, qti, oneroster, caliper, case, nweamap, ed_fi, people_and_orgs, curriculum, content, events, results, analytics.",
          "allowedValues": "module_key",
          "relationship": "Pairs with surface and operation_id for operational reporting.",
          "example": "case",
          "invalidWhen": "Null, outside module_key, set to platform for module resource changes, or used by support tooling as proof that the module surface is approved.",
          "edgeCases": "Service-role maintenance that changes QTI records still uses module=qti; release readiness belongs to module_release_status in the registry and is currently approved for qti/1edtech by loop/qti/state.json. CASE standards-browser maintenance still uses module=case unless the action changes only platform.* rows.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-002 defines module boundaries and PITD-009 requires module in audit rows.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-002-module-schema-boundaries"
          },
          "anchor": "field-platform-audit-log-module"
        },
        {
          "name": "surface",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Audit dimension",
          "meaning": "Surface through which the action was initiated or exposed.",
          "constraints": "Must satisfy surface_code_allowed.",
          "allowedValues": "surface_code",
          "relationship": "Pairs with module and operation_id.",
          "example": "1edtech",
          "invalidWhen": "Null, outside surface_code, or set to alpha for expert-only conformance mutation.",
          "edgeCases": "Background jobs spawned by an Alpha request keep surface=alpha if the customer contract and audit trail originate there.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-015 defines surface model and derivation.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-015-surface-model-and-derivation"
          },
          "anchor": "field-platform-audit-log-surface"
        },
        {
          "name": "operation_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Audit dimension",
          "meaning": "Stable operation identifier from the customer website, OpenAPI, or platform maintenance command.",
          "constraints": "DDL-enforced: nonblank after trimming. Platform convention: use the same lowercase dotted identifier style as platform.idempotency_key.operation_id and match the documented operation whenever an API route triggered the row; audit_log deliberately does not enforce the idempotency regex so legacy and maintenance events can still be audited.",
          "allowedValues": null,
          "relationship": "Same naming convention as platform.idempotency_key.operation_id.",
          "example": "qti.packages.import",
          "invalidWhen": "Blank, derived from localized prose, inconsistent with the endpoint that produced the event, or changed without docs and tests.",
          "edgeCases": "Maintenance operation IDs should be named, such as platform.tenants.backfill-qti-view, not generic maintenance.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 and PITD-010 require operation_id for audit and observability.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-operation-id"
        },
        {
          "name": "actor_subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Pseudonymous actor identifier for the user, service, or release process that attempted the action.",
          "constraints": "Required non-empty text. Use an HMAC/hash or stable opaque subject such as userhash:<hex> or service:<name>. Must not be a name, email, phone number, raw JWT subject, access token, SIS ID, or parent/student contact detail.",
          "allowedValues": null,
          "relationship": "No foreign key. Correlates with auth logs only through redacted identity systems.",
          "example": "userhash:1bd7b5bd0d77",
          "invalidWhen": "Contains @, phone-like text, direct student/parent/teacher name, raw JWT sub, Bearer token, or service credentials.",
          "edgeCases": "For service-role operations use service:<operation-or-system>, and record narrow roles/scopes in actor_roles.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-008 requires pseudonymous learner/customer data in logs and audit rows.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
          },
          "anchor": "field-platform-audit-log-actor-subject"
        },
        {
          "name": "actor_roles",
          "type": "text[]",
          "required": true,
          "default": "'{}'::text[]",
          "key": null,
          "meaning": "Roles or scopes that justified the action or explain why authorization failed.",
          "constraints": "Required array. Values should be lowercase scope/role slugs. Must not include tokens, emails, names, or tenant secrets.",
          "allowedValues": null,
          "relationship": "No foreign key in this dictionary; auth systems remain outside durable audit scope.",
          "example": "{teacher,content-admin}",
          "invalidWhen": "Null, contains raw JWT claims with PII, includes access tokens, or omits the service-role scope for privileged operations.",
          "edgeCases": "An empty array is allowed only when actor_subject is a known service identity and operation_id explains the maintenance path.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 requires explicit roles/scopes for privileged operations.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-audit-log-actor-roles"
        },
        {
          "name": "resource_type",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Resource lookup",
          "meaning": "Stable resource class affected by the action.",
          "constraints": "Required text. Use a table path or public object path such as platform.tenant, qti.content_package, alpha.activity, or qti.conformance_run. Must not include concrete IDs.",
          "allowedValues": null,
          "relationship": "Pairs with resource_id. No database foreign key because target resource tables vary.",
          "example": "qti.content_package",
          "invalidWhen": "Blank, localized title, raw URL, or includes tenant/resource IDs.",
          "edgeCases": "For collection-level denials use a collection type such as qti.content_package with resource_id='unresolved'.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 required resource_type.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-resource-type"
        },
        {
          "name": "resource_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Resource lookup",
          "meaning": "Identifier of the primary resource affected by the action, or a documented sentinel when authorization failed before resource resolution.",
          "constraints": "Required text, 1 to 160 characters. Use the canonical resource ID for resource_type. Use unresolved only for authorization denials before a resource can be safely looked up.",
          "allowedValues": null,
          "relationship": "Pairs with resource_type for support queries.",
          "example": "7f2e4dd2-c147-49ea-af77-41a6fdd70980",
          "invalidWhen": "Blank, direct learner PII, access token, raw path with query secrets, or an ID from another tenant.",
          "edgeCases": "For import operations, resource_id may be the accepted package/job id while module tables later attach child resources.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 required resource_id.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-resource-id"
        },
        {
          "name": "action",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Audit dimension",
          "meaning": "Behavioral category of the audited action.",
          "constraints": "Must satisfy audit_action_allowed.",
          "allowedValues": "audit_action",
          "relationship": "No foreign key. Used with outcome for reporting and incident review.",
          "example": "import",
          "invalidWhen": "Null, outside audit_action, or too vague to distinguish import from create, delete from runtime_delete, or read from read_privileged.",
          "edgeCases": "When one request performs multiple high-risk actions, write multiple audit rows rather than collapsing them into a generic action.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 defines action semantics.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-action"
        },
        {
          "name": "outcome",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Audit dimension",
          "meaning": "Final result category for the action.",
          "constraints": "Must satisfy audit_outcome_allowed.",
          "allowedValues": "audit_outcome",
          "relationship": "No foreign key. Should align with http_status.",
          "example": "succeeded",
          "invalidWhen": "Null, outside audit_outcome, inconsistent with http_status, or hides authorization failure as validation failure.",
          "edgeCases": "Async operations start with accepted; later completion can be represented by a module state change and, when high-risk, another audit row.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 requires outcome and PITD-006 defines status/error policy.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-outcome"
        },
        {
          "name": "http_status",
          "type": "integer",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "HTTP status returned for the request or the HTTP-equivalent status assigned to a background/service operation.",
          "constraints": "Required integer from 100 through 599. Must align with outcome: 2xx for accepted/succeeded, 403 for failed_authorization, 400 for failed_validation, 409/412/428 for failed_conflict, 404 for failed_not_found, and 5xx for failed_server.",
          "allowedValues": null,
          "relationship": "No foreign key. Matches customer-visible Problem/status when the action came from an API route.",
          "example": "201",
          "invalidWhen": "Null, outside 100-599, or inconsistent with outcome.",
          "edgeCases": "For non-HTTP maintenance, use the status the platform would return from the equivalent command API.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 defines HTTP status policy; PITD-009 requires http_status.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-006-http-envelope-and-errors"
          },
          "anchor": "field-platform-audit-log-http-status"
        },
        {
          "name": "request_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Correlation",
          "meaning": "Per-request identifier exposed in Problem responses and support logs.",
          "constraints": "Required non-empty text, 1 to 120 characters. Must be safe to return to customers. Must not include IP addresses, user agents, auth headers, or PII.",
          "allowedValues": null,
          "relationship": "May match platform.idempotency_key.first_request_id for first attempts.",
          "example": "req_20260521_0001",
          "invalidWhen": "Null, blank, contains request headers/secrets, or changes within the same request flow.",
          "edgeCases": "Retries have separate request_id values even when they reuse an idempotency row.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-006 requires requestId in Problem errors and PITD-010 requires structured logs.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-006-http-envelope-and-errors"
          },
          "anchor": "field-platform-audit-log-request-id"
        },
        {
          "name": "trace_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Correlation",
          "meaning": "Trace identifier that links logs, metrics, audit rows, and downstream spans for one request or job.",
          "constraints": "Required non-empty text, 1 to 160 characters. Use W3C traceparent-derived or platform trace ids. Must not include secrets or direct identity data.",
          "allowedValues": null,
          "relationship": "Can appear on multiple audit rows and logs in the same request/job.",
          "example": "trace_20260521_a1f4",
          "invalidWhen": "Null, blank, contains auth tokens, or is regenerated per row inside the same request flow.",
          "edgeCases": "If no distributed tracer is present, set trace_id equal to request_id until tracing is installed.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-010 requires trace_id in structured logs and audit evidence.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-010-observability-and-slos"
          },
          "anchor": "field-platform-audit-log-trace-id"
        },
        {
          "name": "idempotency_key_id",
          "type": "uuid",
          "required": false,
          "default": null,
          "key": "Foreign key",
          "meaning": "Optional link to the idempotency row that governed the audited operation.",
          "constraints": "Nullable. When present, must reference platform.idempotency_key(idempotency_key_id). Set null for operations that do not use Idempotency-Key.",
          "allowedValues": null,
          "relationship": "Many audit rows may refer to one platform.idempotency_key row.",
          "example": "b81db6f4-c7ea-4757-b5aa-87570f7ad119",
          "invalidWhen": "Not a UUID, points to a different tenant, or stores the customer-supplied header value instead of the internal row id.",
          "edgeCases": "On idempotency conflict, the audit row may point at the existing idempotency_key_id while outcome=failed_conflict.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-007 and PITD-009 connect retry behavior to audit.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-idempotency-key-id"
        },
        {
          "name": "occurred_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": "Ordering",
          "meaning": "Timestamp when the audited action reached the recorded outcome.",
          "constraints": "Required timestamp with time zone. Stored in UTC by database convention.",
          "allowedValues": null,
          "relationship": "Used with tenant_id and resource lookup indexes.",
          "example": "2026-05-21T12:01:08Z",
          "invalidWhen": "Null, manually backdated without maintenance evidence, or compared as local time.",
          "edgeCases": "For async accepted work, occurred_at is acceptance time; final job completion has its own module state and possible audit row.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-009 required occurred_at.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
          },
          "anchor": "field-platform-audit-log-occurred-at"
        },
        {
          "name": "redacted_metadata",
          "type": "jsonb",
          "required": true,
          "default": "'{}'::jsonb",
          "key": null,
          "meaning": "Small, safe, structured context that helps explain the audit event without storing raw sensitive data.",
          "constraints": "Must be a JSON object. Allowed content includes counts, hashes, profile names, version numbers, safe problem codes, and redacted summaries. Must not include raw request bodies, tokens, learner names, emails, phone numbers, SIS IDs, raw package bytes, IP addresses, user agents, or direct PII.",
          "allowedValues": null,
          "relationship": "No foreign key. If a metadata field becomes query-critical, promote it to a typed column in a later dictionary attempt.",
          "example": "{\"packageHash\":\"sha256:6a8c1f58c16f4b0b4f0a0d8c6be8d226e3d5d80f0b2f7d2f49e6d7d9e9d4f1cb\",\"resourceCount\":18}",
          "invalidWhen": "Null, non-object JSON, stores secrets/PII/raw bodies, or becomes the only place a required relationship is stored.",
          "edgeCases": "For validation failures, store safe error codes and field names, not the full rejected payload.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-008 and PITD-009 require redacted audit metadata.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
          },
          "anchor": "field-platform-audit-log-redacted-metadata"
        }
      ],
      "anchor": "table-platform-audit-log",
      "sqlComments": "comment on table platform.audit_log is 'This table gives support, compliance, release, and future AI agents one durable account of who did what, under which tenant and module, with what result. Module tables remain the source of record for domain state; audit rows are the redacted narrative that explains sensitive platform actions across modules.';\ncomment on column platform.audit_log.audit_log_id is 'Stable identifier for one append-only audit event.';\ncomment on column platform.audit_log.tenant_id is 'Tenant affected by the audited action.';\ncomment on column platform.audit_log.module is 'Module responsible for the operation being audited.';\ncomment on column platform.audit_log.surface is 'Surface through which the action was initiated or exposed.';\ncomment on column platform.audit_log.operation_id is 'Stable operation identifier from the customer website, OpenAPI, or platform maintenance command.';\ncomment on column platform.audit_log.actor_subject is 'Pseudonymous actor identifier for the user, service, or release process that attempted the action.';\ncomment on column platform.audit_log.actor_roles is 'Roles or scopes that justified the action or explain why authorization failed.';\ncomment on column platform.audit_log.resource_type is 'Stable resource class affected by the action.';\ncomment on column platform.audit_log.resource_id is 'Identifier of the primary resource affected by the action, or a documented sentinel when authorization failed before resource resolution.';\ncomment on column platform.audit_log.action is 'Behavioral category of the audited action.';\ncomment on column platform.audit_log.outcome is 'Final result category for the action.';\ncomment on column platform.audit_log.http_status is 'HTTP status returned for the request or the HTTP-equivalent status assigned to a background/service operation.';\ncomment on column platform.audit_log.request_id is 'Per-request identifier exposed in Problem responses and support logs.';\ncomment on column platform.audit_log.trace_id is 'Trace identifier that links logs, metrics, audit rows, and downstream spans for one request or job.';\ncomment on column platform.audit_log.idempotency_key_id is 'Optional link to the idempotency row that governed the audited operation.';\ncomment on column platform.audit_log.occurred_at is 'Timestamp when the audited action reached the recorded outcome.';\ncomment on column platform.audit_log.redacted_metadata is 'Small, safe, structured context that helps explain the audit event without storing raw sensitive data.';"
    },
    {
      "name": "platform.end_user_identity_binding",
      "title": "End-user identity binding",
      "short": "Durable, operator-authorized binding from one exact Cognito issuer/subject to one People & Orgs person.",
      "purpose": "The TimeBack bridge needs one stable, revocable answer to which current roster person an authenticated Cognito subject represents. It never binds by email and never stores a password or Cognito token.",
      "lifecycle": "Created only by an operator-authorized Bearer request after the legacy invite returns the Cognito subject and People & Orgs confirms the person is real, enabled, non-deleted, and lifecycle-current. Revocation closes the row and every linked browser session. Rebinding inserts history rather than rewriting a revoked row.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "PITD-005 and issue #445 place tenant authentication, subject binding, session lifecycle, and revocation in Platform while People & Orgs remains person/relationship authority.",
      "itds": [
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        },
        {
          "id": "PITD-008",
          "title": "Student Data Privacy And PII Handling",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ],
      "qtiReconciliation": "None. End-user identity is Platform-owned and QTI receives only the short-lived tenant-scoped Bearer claims it is authorized to consume.",
      "primaryKey": "identity_binding_id",
      "relationships": [
        "Many bindings belong to one platform.tenant through tenant_id.",
        "One binding may own many platform.end_user_session rows through the same tenant_id plus identity_binding_id.",
        "person_id is a logical same-tenant reference to People & Orgs because the legacy boundary owns that identifier outside platform.* storage."
      ],
      "constraints": [
        "At most one active row exists for tenant_id + issuer + subject.",
        "At most one active row exists for tenant_id + issuer + person_id.",
        "Revocation timestamp, actor, and reason are either all null or all present."
      ],
      "indexes": [
        "primary key (identity_binding_id)",
        "partial unique (tenant_id, issuer, subject) where revoked_at is null",
        "partial unique (tenant_id, issuer, person_id) where revoked_at is null"
      ],
      "ddl": "create table platform.end_user_identity_binding (\n  identity_binding_id uuid primary key default gen_random_uuid(),\n  tenant_id uuid not null references platform.tenant(tenant_id),\n  issuer text not null,\n  subject text not null,\n  person_id text not null,\n  created_by_subject text not null,\n  created_at timestamptz not null default now(),\n  revoked_at timestamptz,\n  revoked_by_subject text,\n  revocation_reason text,\n  constraint end_user_identity_issuer_ck check (issuer ~ '^https://[^[:space:]]{1,480}$'),\n  constraint end_user_identity_subject_ck check (length(subject) between 1 and 255),\n  constraint end_user_identity_person_ck check (length(person_id) between 1 and 255),\n  constraint end_user_identity_revocation_ck check (\n    (revoked_at is null and revoked_by_subject is null and revocation_reason is null)\n    or (revoked_at is not null and revoked_by_subject is not null and revocation_reason is not null)\n  ),\n  unique (tenant_id, identity_binding_id)\n);\ncreate unique index end_user_identity_active_subject_uidx on platform.end_user_identity_binding(tenant_id, issuer, subject) where revoked_at is null;\ncreate unique index end_user_identity_active_person_uidx on platform.end_user_identity_binding(tenant_id, issuer, person_id) where revoked_at is null;",
      "invalidExamples": [
        "A row created from an email match or without an operator-authorized Bearer request.",
        "Two active Cognito subjects bound to the same People & Orgs person for one issuer.",
        "issuer differs from the configured Amazon Cognito issuer or subject is normalized instead of stored exactly.",
        "A binding stores Cognito access, ID, refresh tokens, password material, email, or names."
      ],
      "example": {
        "identity_binding_id": "41877f4a-d9ce-4b3c-82a4-9cf437212765",
        "tenant_id": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
        "issuer": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_example",
        "subject": "0a1b2c3d-opaque-cognito-subject",
        "person_id": "person_student_001",
        "created_by_subject": "operator:7d29b03c917f1a8ef83c6efb7763ca12",
        "created_at": "2026-08-04T14:00:00Z",
        "revoked_at": null,
        "revoked_by_subject": null,
        "revocation_reason": null
      },
      "queries": [
        "select identity_binding_id, person_id from platform.end_user_identity_binding where tenant_id = $1 and issuer = $2 and subject = $3 and revoked_at is null;",
        "update platform.end_user_identity_binding set revoked_at = now(), revoked_by_subject = $3, revocation_reason = $4 where tenant_id = $1 and identity_binding_id = $2 and revoked_at is null returning identity_binding_id;"
      ],
      "fields": [
        {
          "name": "identity_binding_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable id for one historical binding row.",
          "constraints": "UUID primary key; unique with tenant_id for the session foreign key.",
          "allowedValues": null,
          "relationship": "Parent of many platform.end_user_session rows.",
          "example": "41877f4a-d9ce-4b3c-82a4-9cf437212765",
          "invalidWhen": "Missing, reused, or used without tenant_id for tenant-scoped lookup.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-identity-binding-id"
        },
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Canonical active Platform tenant UUID carried by the binding and local sessions.",
          "constraints": "Must reference platform.tenant(tenant_id); never a tenant key or alias.",
          "allowedValues": null,
          "relationship": "Many bindings belong to one platform.tenant; session-token loads this row before signing its unique tenant_key for downstream APIs.",
          "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
          "invalidWhen": "A module tenant key, a second mapping id, or a tenant outside the operator Bearer scope.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-tenant-id"
        },
        {
          "name": "issuer",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Exact configured HTTPS Cognito issuer.",
          "constraints": "HTTPS URL, at most 480 characters, and exact match to configured Amazon Cognito issuer.",
          "allowedValues": null,
          "relationship": "Pairs with subject as the external identity key.",
          "example": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_example",
          "invalidWhen": "Normalized to another issuer, caller-selected, non-HTTPS, or a hosted UI domain.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-issuer"
        },
        {
          "name": "subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Exact opaque Cognito subject returned by the operator invite and signed ID token.",
          "constraints": "1 to 255 characters; exact match only; never derived from email.",
          "allowedValues": null,
          "relationship": "Unique with tenant_id + issuer while active.",
          "example": "0a1b2c3d-opaque-cognito-subject",
          "invalidWhen": "Email, name, normalized value, token, or a subject from another issuer.",
          "edgeCases": "This is the narrow raw-subject storage exception; audit/session JWT subjects use hashes instead.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-subject"
        },
        {
          "name": "person_id",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Canonical People & Orgs person represented by the bound subject.",
          "constraints": "1 to 255 characters and confirmed current at bind time; authorization is rechecked at every token mint.",
          "allowedValues": null,
          "relationship": "Logical same-tenant reference to People & Orgs alpha.person.",
          "example": "person_student_001",
          "invalidWhen": "Email, SIS identifier, inactive/deleted/test person, or inferred relationship.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-person-id"
        },
        {
          "name": "created_by_subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Pseudonymous hash label for the operator who authorized the binding.",
          "constraints": "Required operator:<32 lowercase hex>; never raw JWT sub or email.",
          "allowedValues": null,
          "relationship": "Correlates to redacted auth/audit evidence without a foreign key.",
          "example": "operator:7d29b03c917f1a8ef83c6efb7763ca12",
          "invalidWhen": "Raw email, name, bearer token, or Cognito end-user subject.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-created-by-subject"
        },
        {
          "name": "created_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Time the binding history row was created.",
          "constraints": "Required UTC timestamp.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "2026-08-04T14:00:00Z",
          "invalidWhen": "Null or rewritten during revocation.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-created-at"
        },
        {
          "name": "revoked_at",
          "type": "timestamptz",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Time the binding stopped authorizing new sessions/tokens.",
          "constraints": "Null while active; present with revoked_by_subject and revocation_reason.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": null,
          "invalidWhen": "Present without actor/reason or cleared to reuse a historical row.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-revoked-at"
        },
        {
          "name": "revoked_by_subject",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Pseudonymous hash label for the revoking operator.",
          "constraints": "Null while active; required with revoked_at and reason.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": null,
          "invalidWhen": "Raw identity, present on an active row, or omitted on revocation.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-revoked-by-subject"
        },
        {
          "name": "revocation_reason",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Bounded operational reason for revocation.",
          "constraints": "Null while active; required when revoked; no PII or token material.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": null,
          "invalidWhen": "Contains email/name/token, or absent when revoked.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-identity-binding-revocation-reason"
        }
      ],
      "anchor": "table-platform-end-user-identity-binding",
      "sqlComments": "comment on table platform.end_user_identity_binding is 'The TimeBack bridge needs one stable, revocable answer to which current roster person an authenticated Cognito subject represents. It never binds by email and never stores a password or Cognito token.';\ncomment on column platform.end_user_identity_binding.identity_binding_id is 'Stable id for one historical binding row.';\ncomment on column platform.end_user_identity_binding.tenant_id is 'Canonical active Platform tenant UUID carried by the binding and local sessions.';\ncomment on column platform.end_user_identity_binding.issuer is 'Exact configured HTTPS Cognito issuer.';\ncomment on column platform.end_user_identity_binding.subject is 'Exact opaque Cognito subject returned by the operator invite and signed ID token.';\ncomment on column platform.end_user_identity_binding.person_id is 'Canonical People & Orgs person represented by the bound subject.';\ncomment on column platform.end_user_identity_binding.created_by_subject is 'Pseudonymous hash label for the operator who authorized the binding.';\ncomment on column platform.end_user_identity_binding.created_at is 'Time the binding history row was created.';\ncomment on column platform.end_user_identity_binding.revoked_at is 'Time the binding stopped authorizing new sessions/tokens.';\ncomment on column platform.end_user_identity_binding.revoked_by_subject is 'Pseudonymous hash label for the revoking operator.';\ncomment on column platform.end_user_identity_binding.revocation_reason is 'Bounded operational reason for revocation.';"
    },
    {
      "name": "platform.end_user_session",
      "title": "End-user session",
      "short": "Opaque first-party browser session whose only credential at rest is a SHA-256 handle hash.",
      "purpose": "The TimeBack bridge keeps browser continuity without persisting Cognito tokens or allowing a cookie to authorize customer APIs. The browser exchanges this session for short-lived Bearer JWTs whose People & Orgs claims are re-derived each time.",
      "lifecycle": "Created after a signed Cognito code+PKCE callback resolves an active binding. Idle expiry advances at successful token mint but never beyond the 2-hour absolute expiry. Logout, expiry, or identity revocation closes the row; invalid-origin attempts fail without advancing it. Closed rows are retained for audit/history.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "PITD-005 and issue #445 define a narrow first-party human-session exception while all customer API calls remain Bearer-only.",
      "itds": [
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        },
        {
          "id": "PITD-008",
          "title": "Student Data Privacy And PII Handling",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ],
      "qtiReconciliation": "None. QTI and every other customer API see only a 600-second Platform Bearer JWT, never this cookie/session row.",
      "primaryKey": "end_user_session_id",
      "relationships": [
        "Many sessions belong to one platform.tenant.",
        "Many sessions belong to one platform.end_user_identity_binding under the same tenant.",
        "No Cognito access, ID, or refresh-token table relates to this row."
      ],
      "constraints": [
        "handle_hash is globally unique and must be sha256:<64 lowercase hex>.",
        "authenticated_at <= last_seen_at < idle_expires_at <= absolute_expires_at.",
        "Revocation timestamp and reason are both null or both present."
      ],
      "indexes": [
        "primary key (end_user_session_id)",
        "unique (handle_hash)",
        "index (tenant_id, identity_binding_id, absolute_expires_at desc)",
        "partial index (absolute_expires_at) where revoked_at is null"
      ],
      "ddl": "create table platform.end_user_session (\n  end_user_session_id uuid primary key default gen_random_uuid(),\n  tenant_id uuid not null references platform.tenant(tenant_id),\n  identity_binding_id uuid not null,\n  handle_hash text not null unique,\n  authenticated_at timestamptz not null,\n  last_seen_at timestamptz not null,\n  idle_expires_at timestamptz not null,\n  absolute_expires_at timestamptz not null,\n  revoked_at timestamptz,\n  revocation_reason text,\n  foreign key (tenant_id, identity_binding_id) references platform.end_user_identity_binding(tenant_id, identity_binding_id),\n  constraint end_user_session_handle_hash_ck check (handle_hash ~ '^sha256:[0-9a-f]{64}$'),\n  constraint end_user_session_lifetime_ck check (authenticated_at <= last_seen_at and last_seen_at < idle_expires_at and idle_expires_at <= absolute_expires_at),\n  constraint end_user_session_revocation_ck check ((revoked_at is null and revocation_reason is null) or (revoked_at is not null and revocation_reason is not null))\n);\ncreate index end_user_session_binding_idx on platform.end_user_session(tenant_id, identity_binding_id, absolute_expires_at desc);\ncreate index end_user_session_expiry_idx on platform.end_user_session(absolute_expires_at) where revoked_at is null;",
      "invalidExamples": [
        "handle_hash contains the raw cookie handle, a reversible encoding, or a Cognito token.",
        "idle_expires_at advances past absolute_expires_at or the row lacks a tenant-scoped binding.",
        "A session-token or logout request is accepted from an origin other than the configured first-party origin.",
        "The session cookie is accepted as authorization by a Content, Curriculum, Results, CASE, or other customer API."
      ],
      "example": {
        "end_user_session_id": "750b24b4-10b3-4625-94f7-5a91076418df",
        "tenant_id": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
        "identity_binding_id": "41877f4a-d9ce-4b3c-82a4-9cf437212765",
        "handle_hash": "sha256:16ff5a9f6f981798c985bb7d32438e6ae2df1cd90c4c08f704d7839c57425913",
        "authenticated_at": "2026-08-04T14:00:00Z",
        "last_seen_at": "2026-08-04T14:05:00Z",
        "idle_expires_at": "2026-08-04T14:35:00Z",
        "absolute_expires_at": "2026-08-04T16:00:00Z",
        "revoked_at": null,
        "revocation_reason": null
      },
      "queries": [
        "select * from platform.end_user_session where tenant_id = $1 and handle_hash = $2;",
        "update platform.end_user_session set revoked_at = now(), revocation_reason = 'identity_binding_revoked' where tenant_id = $1 and identity_binding_id = $2 and revoked_at is null;"
      ],
      "fields": [
        {
          "name": "end_user_session_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable id for one local browser session.",
          "constraints": "UUID primary key.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "750b24b4-10b3-4625-94f7-5a91076418df",
          "invalidWhen": "Missing, reused, or exposed as a browser credential.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-end-user-session-id"
        },
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Canonical Platform tenant UUID that scopes the local session and binding.",
          "constraints": "Must reference platform.tenant and match the binding tenant.",
          "allowedValues": null,
          "relationship": "Many sessions belong to one platform.tenant; its unique tenant_key is signed into downstream People & Orgs and Results JWT tenant fields.",
          "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
          "invalidWhen": "A tenant key is stored in this UUID field or the session points to another tenant's binding.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-tenant-id"
        },
        {
          "name": "identity_binding_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Active subject/person binding that authenticated this session.",
          "constraints": "With tenant_id, references platform.end_user_identity_binding.",
          "allowedValues": null,
          "relationship": "Many sessions belong to one identity binding.",
          "example": "41877f4a-d9ce-4b3c-82a4-9cf437212765",
          "invalidWhen": "Another tenant's binding or a fabricated UUID.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-identity-binding-id"
        },
        {
          "name": "handle_hash",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Unique credential hash",
          "meaning": "SHA-256 of the random 256-bit HttpOnly cookie handle.",
          "constraints": "Unique sha256:<64 lowercase hex>; raw handle is never stored.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "sha256:16ff5a9f6f981798c985bb7d32438e6ae2df1cd90c4c08f704d7839c57425913",
          "invalidWhen": "Raw cookie, JWT, Cognito token, weak digest, or duplicate.",
          "edgeCases": "Lookup compares the hash; the database cannot reconstruct the browser cookie.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-handle-hash"
        },
        {
          "name": "authenticated_at",
          "type": "timestamptz",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Time Cognito callback validation created the session.",
          "constraints": "Required UTC timestamp and no later than last_seen_at.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "2026-08-04T14:00:00Z",
          "invalidWhen": "Null, after last_seen_at, or refreshed without a new login.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-authenticated-at"
        },
        {
          "name": "last_seen_at",
          "type": "timestamptz",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Last successful session-token mint time.",
          "constraints": "At or after authenticated_at and before idle_expires_at.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "2026-08-04T14:05:00Z",
          "invalidWhen": "After expiry or advanced by a failed/cross-origin request.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-last-seen-at"
        },
        {
          "name": "idle_expires_at",
          "type": "timestamptz",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Sliding inactivity deadline, normally 30 minutes after last_seen_at.",
          "constraints": "After last_seen_at and no later than absolute_expires_at.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "2026-08-04T14:35:00Z",
          "invalidWhen": "Past the absolute deadline or advanced without a successful fresh-claims mint.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-idle-expires-at"
        },
        {
          "name": "absolute_expires_at",
          "type": "timestamptz",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Non-extendable deadline, exactly 2 hours after authentication for this contract.",
          "constraints": "At or after idle_expires_at; never updated.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": "2026-08-04T16:00:00Z",
          "invalidWhen": "Extended by activity, absent, or longer than the locked pilot contract.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-absolute-expires-at"
        },
        {
          "name": "revoked_at",
          "type": "timestamptz",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Time logout, expiry, invalid state, or binding revocation closed the session.",
          "constraints": "Null while active; present with revocation_reason.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": null,
          "invalidWhen": "Present without reason or cleared for reuse.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-revoked-at"
        },
        {
          "name": "revocation_reason",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Safe operational reason the session stopped authorizing token mint.",
          "constraints": "Null while active; present when revoked; no direct identity or token material.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform TimeBack bridge.",
          "example": null,
          "invalidWhen": "Contains PII/token or absent on a revoked row.",
          "edgeCases": "Operator and browser routes fail closed rather than guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 and issue #445 define the Platform-owned TimeBack identity/session boundary.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-end-user-session-revocation-reason"
        }
      ],
      "anchor": "table-platform-end-user-session",
      "sqlComments": "comment on table platform.end_user_session is 'The TimeBack bridge keeps browser continuity without persisting Cognito tokens or allowing a cookie to authorize customer APIs. The browser exchanges this session for short-lived Bearer JWTs whose People & Orgs claims are re-derived each time.';\ncomment on column platform.end_user_session.end_user_session_id is 'Stable id for one local browser session.';\ncomment on column platform.end_user_session.tenant_id is 'Canonical Platform tenant UUID that scopes the local session and binding.';\ncomment on column platform.end_user_session.identity_binding_id is 'Active subject/person binding that authenticated this session.';\ncomment on column platform.end_user_session.handle_hash is 'SHA-256 of the random 256-bit HttpOnly cookie handle.';\ncomment on column platform.end_user_session.authenticated_at is 'Time Cognito callback validation created the session.';\ncomment on column platform.end_user_session.last_seen_at is 'Last successful session-token mint time.';\ncomment on column platform.end_user_session.idle_expires_at is 'Sliding inactivity deadline, normally 30 minutes after last_seen_at.';\ncomment on column platform.end_user_session.absolute_expires_at is 'Non-extendable deadline, exactly 2 hours after authentication for this contract.';\ncomment on column platform.end_user_session.revoked_at is 'Time logout, expiry, invalid state, or binding revocation closed the session.';\ncomment on column platform.end_user_session.revocation_reason is 'Safe operational reason the session stopped authorizing token mint.';"
    },
    {
      "name": "platform.producer_credential_grant",
      "title": "Producer-credential grant envelope",
      "short": "Tenant-bound envelope, created once at tenant onboarding, that lets a producer principal self-mint scoped short-lived credentials without any human.",
      "purpose": "Producers (Incept/AP One-class content generators) must obtain scoped credentials such as publish:content through an authenticated API, never a ticket. The grant is the one-time operator onboarding act; everything after it — minting, rotation, self-revocation — is producer self-service bounded by this envelope.",
      "lifecycle": "Created by an operator-authorized Bearer request (operator role or platform:credential:grant scope) for an active tenant. At most one active grant exists per tenant + producer_key and per tenant + bound_subject. Revocation closes the envelope, stops all further minting, and cascades revocation to every outstanding issued credential. A replacement grant inserts a new row rather than rewriting a revoked one.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "Issue #2794 owner ruling (2026-08-10): producers self-serve credentials through authenticated APIs; #2727 is the blocked-customer evidence. PITD-005 owns tenant auth scope; PITD-009 requires issuance/revocation audit rows.",
      "itds": [
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        },
        {
          "id": "PITD-008",
          "title": "Student Data Privacy And PII Handling",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
        }
      ],
      "qtiReconciliation": "None. Consumer modules (Content first) keep verifying ordinary platform HS256 Bearer JWTs; the grant changes who may mint them, not how they are verified.",
      "primaryKey": "grant_id",
      "relationships": [
        "Many grants belong to one platform.tenant through tenant_id.",
        "One grant may own many platform.producer_credential rows through grant_id.",
        "bound_subject is the exact principal subject whose same-tenant Bearer requests may mint under this envelope; it is not a foreign key."
      ],
      "constraints": [
        "allowed_scopes must be a non-empty subset of the enumerated producer_credential_scope vocabulary; wildcard and credential-admin scopes are never grantable.",
        "allowed_roles must be exactly the enumerated producer role class (service).",
        "max_ttl_seconds is bounded to 60..3600; issued credentials are always short-lived.",
        "max_issuances_per_hour is bounded to 1..1000 and enforced fail-closed at mint time.",
        "At most one active row per tenant_id + producer_key and per tenant_id + bound_subject.",
        "Revocation timestamp, actor, and reason are either all null or all present."
      ],
      "indexes": [
        "primary key (grant_id)",
        "partial unique (tenant_id, producer_key) where revoked_at is null",
        "partial unique (tenant_id, bound_subject) where revoked_at is null"
      ],
      "ddl": "create table platform.producer_credential_grant (\n  grant_id uuid primary key default gen_random_uuid(),\n  tenant_id uuid not null references platform.tenant(tenant_id),\n  producer_key text not null,\n  bound_subject text not null,\n  allowed_scopes text[] not null,\n  allowed_roles text[] not null default '{service}'::text[],\n  max_ttl_seconds integer not null default 900,\n  max_issuances_per_hour integer not null default 30,\n  created_by_subject text not null,\n  created_at timestamptz not null default now(),\n  revoked_at timestamptz,\n  revoked_by_subject text,\n  revocation_reason text,\n  constraint producer_grant_producer_key_ck check (producer_key ~ '^[a-z0-9]([a-z0-9-]{1,62}[a-z0-9])$'),\n  constraint producer_grant_bound_subject_ck check (bound_subject ~ '^[A-Za-z0-9._:@/-]{1,160}$'),\n  constraint producer_grant_scopes_enumerated_ck check (allowed_scopes <@ array['author:content', 'publish:content', 'read:content']::text[] and array_length(allowed_scopes, 1) between 1 and 20),\n  constraint producer_grant_roles_enumerated_ck check (allowed_roles <@ array['service']::text[] and array_length(allowed_roles, 1) = 1),\n  constraint producer_grant_ttl_ck check (max_ttl_seconds between 60 and 3600),\n  constraint producer_grant_rate_ck check (max_issuances_per_hour between 1 and 1000),\n  constraint producer_grant_revocation_ck check (\n    (revoked_at is null and revoked_by_subject is null and revocation_reason is null)\n    or (revoked_at is not null and revoked_by_subject is not null and revocation_reason is not null)\n  )\n);\ncreate unique index producer_grant_active_producer_uidx on platform.producer_credential_grant(tenant_id, producer_key) where revoked_at is null;\ncreate unique index producer_grant_active_subject_uidx on platform.producer_credential_grant(tenant_id, bound_subject) where revoked_at is null;",
      "invalidExamples": [
        "A grant whose allowed_scopes contains platform:*, platform:credential:grant, content:*, or any value outside the enumerated producer_credential_scope set.",
        "A grant whose allowed_roles contains operator, issuer, reviewer, or any role other than service.",
        "Two active grants for the same tenant + producer_key, or one bound_subject holding active envelopes in the same tenant twice.",
        "A grant created by a producer credential, a demo principal, or any caller without operator role or platform:credential:grant scope.",
        "A revoked grant that keeps minting, or a revocation that leaves outstanding issued credentials unrevoked."
      ],
      "example": {
        "grant_id": "8c9a4b6e-2f31-4a7d-9b0e-5d1c3e8f7a20",
        "tenant_id": "4fb95b74-06dc-4a8b-8f50-14ce56c93970",
        "producer_key": "ap-one",
        "bound_subject": "ap-one-producer",
        "allowed_scopes": [
          "author:content",
          "publish:content"
        ],
        "allowed_roles": [
          "service"
        ],
        "max_ttl_seconds": 900,
        "max_issuances_per_hour": 30,
        "created_by_subject": "operator-owner",
        "created_at": "2026-08-10T12:00:00Z",
        "revoked_at": null,
        "revoked_by_subject": null,
        "revocation_reason": null
      },
      "queries": [
        "select grant_id, allowed_scopes, allowed_roles, max_ttl_seconds, max_issuances_per_hour from platform.producer_credential_grant where tenant_id = $1 and bound_subject = $2 and revoked_at is null;",
        "update platform.producer_credential_grant set revoked_at = now(), revoked_by_subject = $3, revocation_reason = $4 where tenant_id = $1 and grant_id = $2 and revoked_at is null returning grant_id;"
      ],
      "fields": [
        {
          "name": "grant_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable id for one historical grant envelope row.",
          "constraints": "UUID primary key.",
          "allowedValues": null,
          "relationship": "Parent of many platform.producer_credential rows.",
          "example": "8c9a4b6e-2f31-4a7d-9b0e-5d1c3e8f7a20",
          "invalidWhen": "Missing, reused, or rewritten after revocation.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-grant-id"
        },
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Canonical Platform tenant the envelope is bound to.",
          "constraints": "Must reference platform.tenant(tenant_id); grants exist only for stored tenants.",
          "allowedValues": null,
          "relationship": "Many grants belong to one platform.tenant.",
          "example": "4fb95b74-06dc-4a8b-8f50-14ce56c93970",
          "invalidWhen": "A tenant key, alias, stateless demo handle, or a tenant outside the operator Bearer scope.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-tenant-id"
        },
        {
          "name": "producer_key",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Human-stable lowercase producer identity (for example ap-one).",
          "constraints": "Lowercase slug, 3 to 64 characters; unique per tenant while active.",
          "allowedValues": null,
          "relationship": "Unique with tenant_id while active.",
          "example": "ap-one",
          "invalidWhen": "Free-form display text, uppercase, or a duplicate active producer in the tenant.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-producer-key"
        },
        {
          "name": "bound_subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Exact principal subject whose same-tenant Bearer requests may mint under this envelope.",
          "constraints": "1 to 160 visible non-space characters; exact match at mint time.",
          "allowedValues": null,
          "relationship": "Matched against the authenticated principal subject; issued credentials reuse this subject.",
          "example": "ap-one-producer",
          "invalidWhen": "An email, a pattern/wildcard, the public demo-reader subject for a privileged envelope, or a subject from another tenant.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-bound-subject"
        },
        {
          "name": "allowed_scopes",
          "type": "text[]",
          "required": true,
          "default": null,
          "key": "Envelope bound",
          "meaning": "Exhaustive grantable scope list for this producer; requested scopes must be a subset.",
          "constraints": "Non-empty subset of the enumerated producer_credential_scope vocabulary; at most 20 values.",
          "allowedValues": "producer_credential_scope",
          "relationship": "Bounds platform.producer_credential.scopes for every credential minted under the grant.",
          "example": "{author:content,publish:content}",
          "invalidWhen": "Contains platform:*, platform:credential:grant, or any value outside the enumerated set.",
          "edgeCases": "Widening the vocabulary is a dictionary + migration change, never a runtime decision.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-allowed-scopes"
        },
        {
          "name": "allowed_roles",
          "type": "text[]",
          "required": true,
          "default": "'{service}'::text[]",
          "key": "Envelope bound",
          "meaning": "Role class issued credentials may carry.",
          "constraints": "Exactly one value from the enumerated producer role class (service).",
          "allowedValues": null,
          "relationship": "Bounds platform.producer_credential.roles.",
          "example": "{service}",
          "invalidWhen": "operator, issuer, reviewer, writer, or more than one role.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-allowed-roles"
        },
        {
          "name": "max_ttl_seconds",
          "type": "integer",
          "required": true,
          "default": "900",
          "key": null,
          "meaning": "Upper bound for issued-credential lifetime; also the revocation-convergence horizon for offline verifiers.",
          "constraints": "Integer 60..3600.",
          "allowedValues": null,
          "relationship": "Caps ttlSeconds on every mint under the grant.",
          "example": "900",
          "invalidWhen": "Longer than 3600 seconds; producer credentials are never long-lived static secrets.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-max-ttl-seconds"
        },
        {
          "name": "max_issuances_per_hour",
          "type": "integer",
          "required": true,
          "default": "30",
          "key": null,
          "meaning": "Bounded issuance rate enforced at mint time by counting ledger rows in the trailing hour.",
          "constraints": "Integer 1..1000; exceeding it returns the documented 429 rate_limited Problem.",
          "allowedValues": null,
          "relationship": "Evaluated against platform.producer_credential rows for the grant.",
          "example": "30",
          "invalidWhen": "Bypassed on repository read failure; the rate check fails closed.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-max-issuances-per-hour"
        },
        {
          "name": "created_by_subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Subject of the operator principal that created the envelope at onboarding.",
          "constraints": "Required; never a raw secret or email.",
          "allowedValues": null,
          "relationship": "Correlates to the platform.audit_log create row.",
          "example": "operator-owner",
          "invalidWhen": "A producer credential subject; producer credentials cannot administer grants.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-created-by-subject"
        },
        {
          "name": "created_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Time the envelope was created.",
          "constraints": "Required UTC timestamp.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": "2026-08-10T12:00:00Z",
          "invalidWhen": "Null or rewritten on revocation.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-created-at"
        },
        {
          "name": "revoked_at",
          "type": "timestamptz",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Time the envelope stopped authorizing minting; cascades revocation to outstanding credentials.",
          "constraints": "Null while active; present with actor and reason.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": null,
          "invalidWhen": "Present without actor/reason, or cleared to resurrect a revoked envelope.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-revoked-at"
        },
        {
          "name": "revoked_by_subject",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Subject of the operator that revoked the envelope.",
          "constraints": "Null while active; required with revoked_at.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": null,
          "invalidWhen": "Present on an active row or omitted on revocation.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-revoked-by-subject"
        },
        {
          "name": "revocation_reason",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Bounded operational reason for revocation.",
          "constraints": "Null while active; single line, at most 200 characters; no secrets or PII.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": null,
          "invalidWhen": "Contains a token, email, or is absent when revoked.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-revocation-reason"
        }
      ],
      "anchor": "table-platform-producer-credential-grant",
      "sqlComments": "comment on table platform.producer_credential_grant is 'Producers (Incept/AP One-class content generators) must obtain scoped credentials such as publish:content through an authenticated API, never a ticket. The grant is the one-time operator onboarding act; everything after it — minting, rotation, self-revocation — is producer self-service bounded by this envelope.';\ncomment on column platform.producer_credential_grant.grant_id is 'Stable id for one historical grant envelope row.';\ncomment on column platform.producer_credential_grant.tenant_id is 'Canonical Platform tenant the envelope is bound to.';\ncomment on column platform.producer_credential_grant.producer_key is 'Human-stable lowercase producer identity (for example ap-one).';\ncomment on column platform.producer_credential_grant.bound_subject is 'Exact principal subject whose same-tenant Bearer requests may mint under this envelope.';\ncomment on column platform.producer_credential_grant.allowed_scopes is 'Exhaustive grantable scope list for this producer; requested scopes must be a subset.';\ncomment on column platform.producer_credential_grant.allowed_roles is 'Role class issued credentials may carry.';\ncomment on column platform.producer_credential_grant.max_ttl_seconds is 'Upper bound for issued-credential lifetime; also the revocation-convergence horizon for offline verifiers.';\ncomment on column platform.producer_credential_grant.max_issuances_per_hour is 'Bounded issuance rate enforced at mint time by counting ledger rows in the trailing hour.';\ncomment on column platform.producer_credential_grant.created_by_subject is 'Subject of the operator principal that created the envelope at onboarding.';\ncomment on column platform.producer_credential_grant.created_at is 'Time the envelope was created.';\ncomment on column platform.producer_credential_grant.revoked_at is 'Time the envelope stopped authorizing minting; cascades revocation to outstanding credentials.';\ncomment on column platform.producer_credential_grant.revoked_by_subject is 'Subject of the operator that revoked the envelope.';\ncomment on column platform.producer_credential_grant.revocation_reason is 'Bounded operational reason for revocation.';"
    },
    {
      "name": "platform.producer_credential",
      "title": "Producer credential issuance ledger",
      "short": "Append-only issuance and revocation ledger for self-minted producer credentials; stores only the SHA-256 fingerprint of each issued JWT.",
      "purpose": "Every self-service issuance must be auditable and individually revocable. The ledger row is the durable record the mint route checks before rotation, the revocation switch for one credential, and the join target for issuance/revocation audit rows — while the raw token exists only in the mint response.",
      "lifecycle": "Inserted atomically with each successful mint under an active grant. Rotation inserts a new row; presenting a revoked or unknown credential to the mint route fails closed. Self-revocation (the credential's own subject) or operator revocation closes the row immediately for platform routes; offline verifiers converge within the credential's bounded remaining TTL. Grant revocation cascades revocation with reason grant_revoked.",
      "sourceClass": "Platform shared table",
      "sourceBasis": "Issue #2794 program (a) requires issuance + revocation audit rows and working, fail-closed revocation; PITD-008 forbids storing raw tokens.",
      "itds": [
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        },
        {
          "id": "PITD-008",
          "title": "Student Data Privacy And PII Handling",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ],
      "qtiReconciliation": "None. Issued credentials are ordinary platform HS256 Bearer JWTs carrying the tenant key claim consumer modules already route by.",
      "primaryKey": "credential_id",
      "relationships": [
        "Many credentials belong to one platform.producer_credential_grant through grant_id.",
        "Many credentials belong to one platform.tenant through tenant_id.",
        "platform.audit_log issuance/revocation rows reference credential_id as resource_id; the ledger row, not the audit row, carries the fingerprint."
      ],
      "constraints": [
        "credential_sha256 is globally unique and must be sha256:<64 lowercase hex>; the raw JWT is never stored.",
        "scopes and roles are frozen copies of what was minted and always inside the grant envelope.",
        "expires_at is strictly after issued_at and bounded by the grant max_ttl_seconds.",
        "Revocation timestamp, actor, and reason are either all null or all present."
      ],
      "indexes": [
        "primary key (credential_id)",
        "unique (credential_sha256)",
        "index (grant_id, issued_at desc) — the rate-limit window scan",
        "index (tenant_id, issued_at desc)"
      ],
      "ddl": "create table platform.producer_credential (\n  credential_id uuid primary key default gen_random_uuid(),\n  grant_id uuid not null references platform.producer_credential_grant(grant_id),\n  tenant_id uuid not null references platform.tenant(tenant_id),\n  subject text not null,\n  roles text[] not null,\n  scopes text[] not null,\n  credential_sha256 text not null unique,\n  issued_by_subject text not null,\n  issued_at timestamptz not null default now(),\n  expires_at timestamptz not null,\n  revoked_at timestamptz,\n  revoked_by_subject text,\n  revocation_reason text,\n  constraint producer_credential_subject_ck check (subject ~ '^[A-Za-z0-9._:@/-]{1,160}$'),\n  constraint producer_credential_hash_ck check (credential_sha256 ~ '^sha256:[0-9a-f]{64}$'),\n  constraint producer_credential_scopes_ck check (array_length(scopes, 1) between 1 and 20),\n  constraint producer_credential_roles_ck check (array_length(roles, 1) between 1 and 5),\n  constraint producer_credential_expiry_ck check (expires_at > issued_at),\n  constraint producer_credential_revocation_ck check (\n    (revoked_at is null and revoked_by_subject is null and revocation_reason is null)\n    or (revoked_at is not null and revoked_by_subject is not null and revocation_reason is not null)\n  )\n);\ncreate index producer_credential_grant_issued_idx on platform.producer_credential(grant_id, issued_at desc);\ncreate index producer_credential_tenant_issued_idx on platform.producer_credential(tenant_id, issued_at desc);",
      "invalidExamples": [
        "A row storing the raw JWT, a reversible encoding of it, or the signing secret in any column.",
        "A credential whose scopes or roles exceed its grant envelope.",
        "A revoked credential accepted by the mint/rotate route, or a revoked grant with unrevoked outstanding credentials.",
        "An issuance without a matching platform.audit_log row, or an audit row that carries token-derived strings instead of joining by credential_id."
      ],
      "example": {
        "credential_id": "3f2b8c1d-7e4a-4b9f-8d2c-6a5e9f0b1c3d",
        "grant_id": "8c9a4b6e-2f31-4a7d-9b0e-5d1c3e8f7a20",
        "tenant_id": "4fb95b74-06dc-4a8b-8f50-14ce56c93970",
        "subject": "ap-one-producer",
        "roles": [
          "service"
        ],
        "scopes": [
          "publish:content"
        ],
        "credential_sha256": "sha256:ba216f040c3d109731eb370f6252a989d05e65a3344f88b7e89181ee2a80ba70",
        "issued_by_subject": "ap-one-producer",
        "issued_at": "2026-08-10T12:05:00Z",
        "expires_at": "2026-08-10T12:20:00Z",
        "revoked_at": null,
        "revoked_by_subject": null,
        "revocation_reason": null
      },
      "queries": [
        "select count(*) from platform.producer_credential where grant_id = $1 and issued_at >= now() - interval '1 hour';",
        "update platform.producer_credential set revoked_at = now(), revoked_by_subject = $3, revocation_reason = $4 where tenant_id = $1 and credential_id = $2 returning credential_id;"
      ],
      "fields": [
        {
          "name": "credential_id",
          "type": "uuid",
          "required": true,
          "default": "gen_random_uuid()",
          "key": "Primary key",
          "meaning": "Stable id for one issued credential; also embedded in the JWT as the credential_id claim so rotation and revocation can find this row.",
          "constraints": "UUID primary key.",
          "allowedValues": null,
          "relationship": "Referenced by audit rows and by the credential_id JWT claim.",
          "example": "3f2b8c1d-7e4a-4b9f-8d2c-6a5e9f0b1c3d",
          "invalidWhen": "Missing from the minted JWT or reused across issuances.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-credential-id"
        },
        {
          "name": "grant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Grant envelope the credential was minted under.",
          "constraints": "Must reference platform.producer_credential_grant(grant_id).",
          "allowedValues": null,
          "relationship": "Many credentials belong to one grant.",
          "example": "8c9a4b6e-2f31-4a7d-9b0e-5d1c3e8f7a20",
          "invalidWhen": "Another tenant's grant or a revoked envelope at mint time.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-grant-id"
        },
        {
          "name": "tenant_id",
          "type": "uuid",
          "required": true,
          "default": null,
          "key": "Foreign key",
          "meaning": "Canonical Platform tenant the credential is bound to.",
          "constraints": "Must reference platform.tenant(tenant_id) and equal the grant tenant.",
          "allowedValues": null,
          "relationship": "Many credentials belong to one platform.tenant.",
          "example": "4fb95b74-06dc-4a8b-8f50-14ce56c93970",
          "invalidWhen": "Differs from the grant tenant; tenant binding is enforced server-side.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-tenant-id"
        },
        {
          "name": "subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Principal subject carried by the issued JWT; always the grant bound_subject.",
          "constraints": "1 to 160 visible non-space characters.",
          "allowedValues": null,
          "relationship": "Equals platform.producer_credential_grant.bound_subject.",
          "example": "ap-one-producer",
          "invalidWhen": "A caller-chosen subject different from the envelope binding.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-subject"
        },
        {
          "name": "roles",
          "type": "text[]",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Frozen role list minted into the JWT.",
          "constraints": "Non-empty subset of the grant allowed_roles; 1 to 5 values.",
          "allowedValues": null,
          "relationship": "Bounded by platform.producer_credential_grant.allowed_roles.",
          "example": "{service}",
          "invalidWhen": "Any role outside the envelope.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-roles"
        },
        {
          "name": "scopes",
          "type": "text[]",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Frozen scope list minted into the JWT.",
          "constraints": "Non-empty subset of the grant allowed_scopes; 1 to 20 values.",
          "allowedValues": "producer_credential_scope",
          "relationship": "Bounded by platform.producer_credential_grant.allowed_scopes.",
          "example": "{publish:content}",
          "invalidWhen": "Any scope outside the envelope; escalation attempts are refused and audited as authz_denied.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-scopes"
        },
        {
          "name": "credential_sha256",
          "type": "text",
          "required": true,
          "default": null,
          "key": "Unique credential fingerprint",
          "meaning": "SHA-256 fingerprint of the issued JWT; the only stored representation of the secret.",
          "constraints": "Unique sha256:<64 lowercase hex>.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": "sha256:ba216f040c3d109731eb370f6252a989d05e65a3344f88b7e89181ee2a80ba70",
          "invalidWhen": "The raw JWT, a truncated digest, or a duplicate fingerprint.",
          "edgeCases": "The database cannot reconstruct the token; a leaked ledger row grants nothing.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-credential-sha256"
        },
        {
          "name": "issued_by_subject",
          "type": "text",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "Subject of the principal that requested the mint (the bootstrap principal or the rotating credential's subject).",
          "constraints": "Required; never a raw secret.",
          "allowedValues": null,
          "relationship": "Correlates to the platform.audit_log issuance row.",
          "example": "ap-one-producer",
          "invalidWhen": "Empty or an unauthenticated placeholder.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-issued-by-subject"
        },
        {
          "name": "issued_at",
          "type": "timestamptz",
          "required": true,
          "default": "now()",
          "key": null,
          "meaning": "Mint time; the rate-limit window counts rows by this column.",
          "constraints": "Required UTC timestamp equal to the JWT iat.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": "2026-08-10T12:05:00Z",
          "invalidWhen": "Backdated to evade the issuance rate bound.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-issued-at"
        },
        {
          "name": "expires_at",
          "type": "timestamptz",
          "required": true,
          "default": null,
          "key": null,
          "meaning": "JWT exp; the credential is useless everywhere after this time.",
          "constraints": "Strictly after issued_at; at most grant max_ttl_seconds later.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": "2026-08-10T12:20:00Z",
          "invalidWhen": "More than 3600 seconds after issuance.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-expires-at"
        },
        {
          "name": "revoked_at",
          "type": "timestamptz",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Time the credential stopped being accepted by platform producer-credential routes.",
          "constraints": "Null while active; present with actor and reason.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": null,
          "invalidWhen": "Cleared to resurrect a revoked credential.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-revoked-at"
        },
        {
          "name": "revoked_by_subject",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Subject that revoked the credential: its own producer principal (self-revoke on suspected leak), an operator, or the grant revocation cascade.",
          "constraints": "Null while active; required with revoked_at.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": null,
          "invalidWhen": "A subject that is neither the credential owner nor a grant administrator.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-revoked-by-subject"
        },
        {
          "name": "revocation_reason",
          "type": "text",
          "required": false,
          "default": null,
          "key": null,
          "meaning": "Bounded operational reason; the grant cascade writes grant_revoked.",
          "constraints": "Null while active; single line, at most 200 characters.",
          "allowedValues": null,
          "relationship": "No foreign key; interpreted only by the Platform producer-credential routes.",
          "example": null,
          "invalidWhen": "Contains a token or PII.",
          "edgeCases": "Producer-credential routes fail closed rather than widening an envelope or guessing a value.",
          "provenance": {
            "label": "Platform shared",
            "basis": "PITD-005 plus issues #2727/#2794 place self-service, tenant-bound, auditable producer-credential provisioning in Platform tenant onboarding.",
            "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
          },
          "anchor": "field-platform-producer-credential-revocation-reason"
        }
      ],
      "anchor": "table-platform-producer-credential",
      "sqlComments": "comment on table platform.producer_credential is 'Every self-service issuance must be auditable and individually revocable. The ledger row is the durable record the mint route checks before rotation, the revocation switch for one credential, and the join target for issuance/revocation audit rows — while the raw token exists only in the mint response.';\ncomment on column platform.producer_credential.credential_id is 'Stable id for one issued credential; also embedded in the JWT as the credential_id claim so rotation and revocation can find this row.';\ncomment on column platform.producer_credential.grant_id is 'Grant envelope the credential was minted under.';\ncomment on column platform.producer_credential.tenant_id is 'Canonical Platform tenant the credential is bound to.';\ncomment on column platform.producer_credential.subject is 'Principal subject carried by the issued JWT; always the grant bound_subject.';\ncomment on column platform.producer_credential.roles is 'Frozen role list minted into the JWT.';\ncomment on column platform.producer_credential.scopes is 'Frozen scope list minted into the JWT.';\ncomment on column platform.producer_credential.credential_sha256 is 'SHA-256 fingerprint of the issued JWT; the only stored representation of the secret.';\ncomment on column platform.producer_credential.issued_by_subject is 'Subject of the principal that requested the mint (the bootstrap principal or the rotating credential''s subject).';\ncomment on column platform.producer_credential.issued_at is 'Mint time; the rate-limit window counts rows by this column.';\ncomment on column platform.producer_credential.expires_at is 'JWT exp; the credential is useless everywhere after this time.';\ncomment on column platform.producer_credential.revoked_at is 'Time the credential stopped being accepted by platform producer-credential routes.';\ncomment on column platform.producer_credential.revoked_by_subject is 'Subject that revoked the credential: its own producer principal (self-revoke on suspected leak), an operator, or the grant revocation cascade.';\ncomment on column platform.producer_credential.revocation_reason is 'Bounded operational reason; the grant cascade writes grant_revoked.';"
    }
  ],
  "enumSets": [
    {
      "name": "tenant_status",
      "purpose": "Lifecycle state for platform.tenant rows. Modules must reject new customer writes unless the tenant is active.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model",
      "values": [
        {
          "value": "provisioning",
          "meaning": "The tenant row exists, but required setup such as auth, domains, or integrations is not complete.",
          "useWhen": "Create this before the tenant can ingest content, launch learner activity, or receive production traffic.",
          "invalidWhen": "Used for a tenant that is already accepting module writes."
        },
        {
          "value": "active",
          "meaning": "Normal customer state. Tenant-scoped reads and writes may proceed when the JWT tenant claim and role checks pass.",
          "useWhen": "The tenant is fully configured and in good standing.",
          "invalidWhen": "Used while required onboarding, suspension, or archival conditions are unresolved."
        },
        {
          "value": "suspended",
          "meaning": "The tenant is known but temporarily blocked from ordinary customer writes.",
          "useWhen": "Billing, security, contract, or incident response requires stopping writes without deleting history.",
          "invalidWhen": "Used to hide a tenant that should be permanently archived or deleted through a documented retention flow."
        },
        {
          "value": "archived",
          "meaning": "The tenant is retained for history and audit, but new module writes are rejected except explicit maintenance or export flows.",
          "useWhen": "A customer relationship ended or a workspace was retired and records must remain queryable for retention.",
          "invalidWhen": "Used as a soft substitute for learner-runtime deletion, which belongs to module-specific learner data flows."
        }
      ]
    },
    {
      "name": "module_key",
      "purpose": "Canonical module identifier stored in shared platform records. These values cover every documented shared-Supabase writer namespace allowed to create platform.idempotency_key and platform.audit_log rows. This is stable identity only; it does not mean a module surface is currently approved. A future writer becomes legal only when a later Platform data-dictionary and migration attempt adds its module_key value deliberately; raw free-form module strings are never accepted.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-002-module-schema-boundaries",
      "values": [
        {
          "value": "platform",
          "meaning": "Shared platform substrate, documentation, auth, idempotency, audit, and cross-module operations.",
          "useWhen": "The operation belongs to the platform surface itself, shared middleware, release tooling, or a cross-module administrative API.",
          "invalidWhen": "Used for a module-owned resource mutation that should remain attributed to its owning writer namespace."
        },
        {
          "value": "incept",
          "meaning": "Incept producer-surface namespace for governed generation, evaluation, model-grid, source, quality, repair, promotion, deployment, and issue-link provenance.",
          "useWhen": "The operation writes, projects, audits, or reads the governed Incept ledger/projection objects listed under PITD-032 and needs shared audit/idempotency attribution.",
          "invalidWhen": "Used as a consumer-facing Content, Results, Events, or Analytics substitute, or used to justify direct SUPABASE_DB_URL reads from an Incept app."
        },
        {
          "value": "qti",
          "meaning": "Question and Test Interoperability module namespace for assessment content, runtime, conformance, package import/export, and Alpha assessment facade operations.",
          "useWhen": "The operation touches QTI-owned records and the calling surface is allowed by the current release state derived from loop/qti/state.json.",
          "invalidWhen": "Used as a release-status signal, or used for roster, telemetry, standards, MAP, SIS, Alpha learning-surface, or platform-only administrative operations."
        },
        {
          "value": "oneroster",
          "meaning": "OneRoster module namespace for roster, enrollment, class, school, user, course, and academic-session contracts.",
          "useWhen": "The operation touches OneRoster-owned roster data, import/export work, conformance evidence, or the OneRoster integration app.",
          "invalidWhen": "Used for QTI assessment resources, Caliper event telemetry, CASE standards data, NWEAMap rows, Ed-Fi records, Alpha facade rows, or platform-only tenant administration."
        },
        {
          "value": "caliper",
          "meaning": "Caliper Analytics module namespace for event telemetry and metric-profile contracts.",
          "useWhen": "The operation touches Caliper event ingest, metric-profile validation, event-store reads, or the Caliper integration app.",
          "invalidWhen": "Used for QTI assessment content, OneRoster roster resources, CASE standards data, NWEAMap rows, Ed-Fi records, Alpha facade rows, or platform-only tenant administration."
        },
        {
          "value": "case",
          "meaning": "CASE module namespace for CFDocument, CFItem, CFAssociation, CFPackage, and Alignment contracts.",
          "useWhen": "The operation touches CASE standards data, package import/export, graph reads, external-ID alignment, or the CASE integration app.",
          "invalidWhen": "Used for QTI assessment content, OneRoster roster resources, Caliper telemetry, NWEAMap rows, Ed-Fi records, Alpha facade rows, or platform-only tenant administration."
        },
        {
          "value": "nweamap",
          "meaning": "NWEAMap sibling module namespace for MAP Growth export ingest, deduped test-of-record views, goal-strand rows, and NWEA account-scoped results.",
          "useWhen": "The operation imports NWEA CDF data, reconciles retakes, exposes NWEAMap 1EdTech rows, or writes audit/idempotency records for MAP-specific platform behavior.",
          "invalidWhen": "Used for Alpha Results rollups, generic assessment content, SIS administrative records, or non-MAP analytics."
        },
        {
          "value": "ed_fi",
          "meaning": "Ed-Fi sibling module namespace for SIS-style administrative records such as attendance, guardians, program participation, transcripts, discipline, demographics, staff, and descriptors.",
          "useWhen": "The operation imports, validates, reads, or reconciles Ed-Fi-shaped school records and needs shared audit/idempotency attribution.",
          "invalidWhen": "Used for OneRoster identity truth, TimeBack learning facts, MAP results, or Alpha plain-language facade rows."
        },
        {
          "value": "people_and_orgs",
          "meaning": "Alpha People & Orgs namespace for plain-language students, parents, guides, staff, schools, districts, levels, and effective-dated memberships over the shared roster base.",
          "useWhen": "The operation serves or writes the Alpha People & Orgs facade, source-shaped migration normalization, or school-language roster membership views.",
          "invalidWhen": "Used for raw OneRoster 1EdTech endpoints, SIS-only Ed-Fi records, learning results, or curriculum/content operations."
        },
        {
          "value": "curriculum",
          "meaning": "Alpha Curriculum namespace for knowledge components, tracks, courses, course components, gates, remediation sequencing, policies, and learning-engine placement/routing state that is the same for every student.",
          "useWhen": "The operation authors, imports, routes, gates, remediates, or reconciles Curriculum-owned rows and needs shared audit/idempotency attribution.",
          "invalidWhen": "Used for student-specific Results mastery state, flat Content assets, Caliper Events, or OneRoster roster facts."
        },
        {
          "value": "content",
          "meaning": "Alpha Content namespace for student-touchable assets: questions, stimuli, tests, test specs, test banks, articles, videos, audio, images, interactives, media assets, external links, scripts, and reusable banks.",
          "useWhen": "The operation creates, imports, catalogs, renders, or reconciles Content-owned rows and needs retry/audit attribution.",
          "invalidWhen": "Used for Curriculum sequencing, Results attempts/scores, Analytics rollups, or Events telemetry."
        },
        {
          "value": "events",
          "meaning": "Alpha Events namespace for timestamped student interactions and Caliper-derived moments before they become settled results or rollups.",
          "useWhen": "The operation ingests, validates, reads, or reconciles learner interaction events and needs shared audit/idempotency attribution.",
          "invalidWhen": "Used for durable scores/mastery, derived Analytics measures, Content assets, or Curriculum structure."
        },
        {
          "value": "results",
          "meaning": "Alpha Results namespace for durable student outcomes: test scores, gate passes, mastery state, working grade, report-card facts, XP awards, and Results-owned derived overlays.",
          "useWhen": "The operation writes, imports, reconciles, or reads settled Results facts and needs shared audit/idempotency attribution.",
          "invalidWhen": "Used for the original interaction event, raw Content, Curriculum policy, or Analytics window rollups."
        },
        {
          "value": "analytics",
          "meaning": "Alpha Analytics namespace for typed derived facts and per-window rollups such as active/inactive/waste seconds, mastery deltas, XP totals, growth measures, and reporting views.",
          "useWhen": "The operation computes, materializes, refreshes, or reads Analytics-owned rollups and needs shared audit/idempotency attribution.",
          "invalidWhen": "Used for system-of-record Events, settled Results, source Content, or roster/Curriculum facts."
        }
      ]
    },
    {
      "name": "incept_traffic_class",
      "purpose": "Traffic class for Incept producer events. Headline customer Accuracy counts only customer traffic; owner-directed goal work and loop self-tests stay visible in drilldown lanes without moving the customer headline metric.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface",
      "values": [
        {
          "value": "customer",
          "meaning": "Customer-shaped generation or evaluation traffic that should count in the public headline Accuracy numerator and denominator.",
          "useWhen": "A user/customer-facing request, production progress projection, or legacy row without an explicit trafficClass is being reported as customer availability or quality.",
          "invalidWhen": "Used for owner-directed course/materialization runs, backfills, repair probes, CI checks, or loop self-tests."
        },
        {
          "value": "goal-run",
          "meaning": "Owner-directed work to materialize a stated goal, backfill a course, execute a repair, or advance a known bottleneck.",
          "useWhen": "The run exists because the owner or factory selected a tactical goal, including bulk course/content materialization and repair execution.",
          "invalidWhen": "Used for ordinary customer traffic or for automated self-tests whose purpose is only to verify the loop machinery."
        },
        {
          "value": "self-test",
          "meaning": "Loop, CI, reviewer, smoke, or synthetic traffic whose purpose is to verify machinery rather than satisfy a customer request or owner goal.",
          "useWhen": "The event comes from a test harness, reviewer check, synthetic fixture, or smoke probe.",
          "invalidWhen": "Used for real customer traffic or for owner-directed goal execution that should be tracked in the goal-run lane."
        }
      ]
    },
    {
      "name": "module_release_status",
      "purpose": "Current release state exposed by the platform module registry and customer docs. It is derived from loop state, not from module_key values in platform.idempotency_key or platform.audit_log.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-013-loop-execution-durable-state",
      "values": [
        {
          "value": "approved",
          "meaning": "The named module surface has passed the loop through its required release gate and may be advertised to cold integrators.",
          "useWhen": "Every required deliverable for that surface is currently approved in loop/<module>/state.json.",
          "invalidWhen": "Any required deliverable for that surface is doing, reviewing, changes_requested, rolled_back, or not_started."
        },
        {
          "value": "under_reconciliation",
          "meaning": "A previously published or linked surface is withdrawn while it is rebuilt against newer platform truth.",
          "useWhen": "The loop has rolled back that surface or restarted an upstream deliverable to reconcile a platform contract, but the module namespace remains valid for existing audit/idempotency rows.",
          "invalidWhen": "Used for a brand-new surface that was never published, or used to imply the public API is ready for new cold integrators."
        },
        {
          "value": "in_progress",
          "meaning": "The surface is being built and has not yet reached the customer-facing release gate.",
          "useWhen": "A current deliverable is doing, reviewing, or changes_requested and there is no previously approved public surface being withdrawn.",
          "invalidWhen": "Used after a rollback has invalidated previously advertised docs or API behavior."
        },
        {
          "value": "rolled_back",
          "meaning": "A surface deliverable has been explicitly invalidated and must not be treated as public release truth.",
          "useWhen": "loop/<module>/state.json marks the relevant deliverable or a required downstream deliverable as rolled_back.",
          "invalidWhen": "Used as a customer-facing substitute for under_reconciliation when the registry still lists the module surface."
        },
        {
          "value": "not_started",
          "meaning": "The module surface has no current approved or in-flight release surface.",
          "useWhen": "The surface entries are not_started in loop/<module>/state.json.",
          "invalidWhen": "Used for a surface with approved artifacts or an active current deliverable."
        }
      ]
    },
    {
      "name": "surface_code",
      "purpose": "Which public or internal surface produced the shared record.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-015-surface-model-and-derivation",
      "values": [
        {
          "value": "platform",
          "meaning": "The platform substrate surface.",
          "useWhen": "The route, audit row, idempotency scope, or dictionary entry is cross-module rather than standard-specific.",
          "invalidWhen": "Used to mask whether a QTI expert or Alpha customer endpoint produced a module action."
        },
        {
          "value": "incept",
          "meaning": "The producer-writer identity for governed Incept ledger and projection rows.",
          "useWhen": "A Platform3-native Incept write/readback path records generation-loop provenance under PITD-032.",
          "invalidWhen": "Treated as a third consumer API surface or as permission to bypass Platform3 auth, tenant scope, audit, and data-dictionary rules."
        },
        {
          "value": "1edtech",
          "meaning": "Expert standards surface that follows a 1EdTech specification exactly except documented gap fills.",
          "useWhen": "The operation is on an expert API or documentation surface for a 1EdTech standard.",
          "invalidWhen": "Used for Alpha facade calls that rename, restrict, cut, or extend standard language."
        },
        {
          "value": "alpha",
          "meaning": "Plain-language customer and app-builder surface over the same persistence model.",
          "useWhen": "The operation comes from an Alpha API or documentation surface.",
          "invalidWhen": "Used for expert-only conformance mutation, standards package internals, or release tooling."
        }
      ]
    },
    {
      "name": "mutation_http_method",
      "purpose": "HTTP methods eligible for shared idempotency tracking.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency",
      "values": [
        {
          "value": "POST",
          "meaning": "Create, import, upload, command, or async job operation where a network retry might duplicate work.",
          "useWhen": "The route creates work or resources and the customer site documents Idempotency-Key.",
          "invalidWhen": "Used for a read-only GET."
        },
        {
          "value": "PUT",
          "meaning": "Full replacement mutation that may be retried by a client.",
          "useWhen": "The route is documented as retryable and uses If-Match or another validator if it can overwrite user work.",
          "invalidWhen": "Used without a request hash and concurrency rule."
        },
        {
          "value": "PATCH",
          "meaning": "Partial update mutation that may be retried by a client.",
          "useWhen": "The route is documented as retryable and a duplicate patch must not apply twice.",
          "invalidWhen": "Used for non-repeatable patch semantics that the customer site has not made idempotent."
        },
        {
          "value": "DELETE",
          "meaning": "Delete or redaction command where retrying should not produce a second distinct deletion event.",
          "useWhen": "The route documents retry behavior and audit requirements.",
          "invalidWhen": "Used for implicit retention cleanup that is not customer-visible or not keyed by Idempotency-Key."
        }
      ]
    },
    {
      "name": "idempotency_status",
      "purpose": "Replay lifecycle for platform.idempotency_key rows.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency",
      "values": [
        {
          "value": "in_progress",
          "meaning": "The first request claimed the key and the operation has not reached a final replayable outcome.",
          "useWhen": "The handler starts work and stores a lock before performing the mutation.",
          "invalidWhen": "Retained after locked_until has passed without stale-lock-reclaim, completion, or failure handling."
        },
        {
          "value": "completed",
          "meaning": "The operation reached a successful replayable outcome. Same key plus same request hash returns the stored response.",
          "useWhen": "The mutation committed and response_status/response_body or resource pointers are safe to replay.",
          "invalidWhen": "Used when the committed resource is unknown or the stored response contains secrets or learner PII."
        },
        {
          "value": "failed_permanent",
          "meaning": "The original request reached a final caller-fixable error such as validation, authorization, conflict, or precondition failure.",
          "useWhen": "Replaying the same invalid request should return the same safe Problem response instead of re-running side effects.",
          "invalidWhen": "Used for transient 5xx failures that should be retried after the lock expires."
        },
        {
          "value": "failed_transient",
          "meaning": "The first attempt failed without a replayable response, but rerunning the same request is safe.",
          "useWhen": "A dependency or server failure happened before platform-owned side effects, all platform-owned side effects rolled back with the claim transaction, or the operation is internally idempotent under the same request_hash; after locked_until, the same request may reclaim the row under stale_lock_reclaimed.",
          "invalidWhen": "Used after a database mutation might have committed without a response."
        },
        {
          "value": "commit_uncertain",
          "meaning": "The worker cannot prove whether platform-owned side effects committed, and no safe replay body exists.",
          "useWhen": "Only when the handler cannot immediately prove rollback, reconstruct a completed response, or produce a failed_permanent Problem. The row is non-reclaimable; retries return idempotency_commit_uncertain until module-specific reconciliation resolves the outcome.",
          "invalidWhen": "Used for a failure known to have happened before side effects, or for an operation that is internally idempotent and safe to rerun under failed_transient."
        },
        {
          "value": "expired",
          "meaning": "The key is retained only for audit or conflict explanation after its replay window has ended.",
          "useWhen": "expires_at has passed and the platform cleanup policy marks the row no longer replayable.",
          "invalidWhen": "Used to avoid returning a known conflict inside the documented replay window."
        }
      ]
    },
    {
      "name": "audit_action",
      "purpose": "Kind of customer-visible or high-risk action captured by platform.audit_log.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log",
      "values": [
        {
          "value": "create",
          "meaning": "A resource was created synchronously.",
          "useWhen": "The operation inserts a module or platform row that customers can later read.",
          "invalidWhen": "Used for import jobs that should be action=import."
        },
        {
          "value": "update",
          "meaning": "An existing resource was changed.",
          "useWhen": "A mutable customer or administrative field changes.",
          "invalidWhen": "Used for append-only learner submission creation."
        },
        {
          "value": "delete",
          "meaning": "A reusable resource or tenant-scoped object was deleted or archived.",
          "useWhen": "The operation removes or retires content, settings, or a non-runtime record.",
          "invalidWhen": "Used for learner-runtime deletion, which must be runtime_delete."
        },
        {
          "value": "import",
          "meaning": "A package, roster, event batch, or standards bundle was accepted for ingest.",
          "useWhen": "The operation takes external source material and projects it into module tables.",
          "invalidWhen": "Used for manual object creation that has no source package or batch."
        },
        {
          "value": "export",
          "meaning": "A customer or service-role actor generated an exportable data view.",
          "useWhen": "The operation produces a file, report, or export job with customer data.",
          "invalidWhen": "Used for ordinary API reads."
        },
        {
          "value": "read_privileged",
          "meaning": "A read occurred through service-role, support, release, or other privileged authority.",
          "useWhen": "The read would not be available to an ordinary tenant-scoped caller.",
          "invalidWhen": "Used for normal customer GETs that are already covered by access logs."
        },
        {
          "value": "runtime_delete",
          "meaning": "Learner runtime data was deleted or redacted under a student-data lifecycle rule.",
          "useWhen": "A student, parent, school, or retention process removes learner-specific state.",
          "invalidWhen": "Used for reusable content deletion."
        },
        {
          "value": "conformance_change",
          "meaning": "A release or expert path changed conformance evidence.",
          "useWhen": "A conformance run starts, finishes, fails, or changes trust-relevant assertions.",
          "invalidWhen": "Used for read-only Alpha trust status views."
        },
        {
          "value": "trust_change",
          "meaning": "Public trust status changed as a result of evidence, rollback, or release gating.",
          "useWhen": "A customer-visible trust summary moves between trusted, degraded, failed, or unknown states.",
          "invalidWhen": "Used for ordinary audit actions that do not change public trust."
        },
        {
          "value": "authz_denied",
          "meaning": "An authenticated caller was denied by tenant, role, scope, service-role, or operation authorization.",
          "useWhen": "The request had an authenticated subject but failed authorization.",
          "invalidWhen": "Used for missing or invalid authentication; those are security logs, not tenant audit rows."
        },
        {
          "value": "maintenance",
          "meaning": "A named platform or service-role maintenance operation touched durable state.",
          "useWhen": "Backfills, compatibility migrations, cleanup, or incident response make controlled changes.",
          "invalidWhen": "Used as a generic label when a more specific action exists."
        }
      ]
    },
    {
      "name": "audit_outcome",
      "purpose": "Final result of the audited action.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log",
      "values": [
        {
          "value": "accepted",
          "meaning": "The platform accepted work for asynchronous processing and returned a trackable resource.",
          "useWhen": "The HTTP status is usually 202 and later completion is represented by another row or resource state.",
          "invalidWhen": "Used after the work has already succeeded or failed."
        },
        {
          "value": "succeeded",
          "meaning": "The action completed successfully.",
          "useWhen": "The HTTP status is 2xx and the intended state transition committed.",
          "invalidWhen": "Used when only validation passed but async work is still pending."
        },
        {
          "value": "failed_validation",
          "meaning": "The action was rejected because caller-supplied data was malformed or semantically invalid.",
          "useWhen": "The HTTP status is usually 400 or 422-style validation mapped to 400 by platform docs.",
          "invalidWhen": "Used for authorization or conflict failures."
        },
        {
          "value": "failed_authorization",
          "meaning": "The authenticated caller lacked tenant, role, scope, service-role, or operation authority.",
          "useWhen": "The HTTP status is 403.",
          "invalidWhen": "Used for missing Bearer token, which should not create a tenant audit row."
        },
        {
          "value": "failed_conflict",
          "meaning": "The action conflicted with idempotency, uniqueness, state version, lifecycle, or resource state.",
          "useWhen": "The HTTP status is 409, 412, or 428.",
          "invalidWhen": "Used for not-found conditions."
        },
        {
          "value": "failed_not_found",
          "meaning": "The resource was absent or not visible inside the authenticated tenant scope.",
          "useWhen": "The HTTP status is 404 and the action was high-risk enough to audit.",
          "invalidWhen": "Used to leak existence of resources outside the tenant."
        },
        {
          "value": "failed_server",
          "meaning": "The action failed because of unexpected platform, dependency, runner, or storage behavior.",
          "useWhen": "The HTTP status is 5xx or equivalent background-job failure.",
          "invalidWhen": "Used for caller-fixable validation problems."
        }
      ]
    },
    {
      "name": "producer_credential_scope",
      "purpose": "Exhaustive vocabulary of scopes a producer-credential grant envelope may enumerate and a self-minted producer credential may carry. Everything outside this list — wildcards, credential-admin scopes, token-issue scopes — is never grantable; widening the vocabulary is a deliberate dictionary + migration change.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope",
      "values": [
        {
          "value": "author:content",
          "meaning": "Create and edit draft Content items, versions, media, references, and KC tags in the producer's own tenant.",
          "useWhen": "The producer authors test_spec/test_bank/article/video graphs or imports QTI packages before publication.",
          "invalidWhen": "Used to publish; authoring authority deliberately does not include the publication step."
        },
        {
          "value": "publish:content",
          "meaning": "Invoke governed Content publication (recipe-content-publication) on the producer's own tenant; Content's kind-owned QC remains the release gate.",
          "useWhen": "The producer moves authored drafts to published+trusted exact versions through POST .../items/{contentId}/publish.",
          "invalidWhen": "Treated as a QC bypass, used cross-tenant, or granted to end-user (student/teacher/demo) principals."
        },
        {
          "value": "read:content",
          "meaning": "Read Content catalog, item, version, trust, and release-eligibility state in the producer's own tenant.",
          "useWhen": "The producer verifies authored or published state by readback.",
          "invalidWhen": "Used as a substitute for module-specific read authority outside Content."
        }
      ]
    }
  ],
  "dictionaryConventions": [
    {
      "id": "entry-completeness",
      "title": "Entry Completeness",
      "rule": "Every table section must include purpose, lifecycle, source/provenance, ITD links, primary key, relationships, constraints, invalid examples, example row, query snippets, and indexes. Every field row must include type, required/nullability, default, key role, meaning, constraints, allowed values, relationship/cardinality, example, invalidWhen, edge cases, and provenance.",
      "why": "A staff engineer must be able to write a migration and a query without reading source code.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-014-data-dictionary-provenance"
    },
    {
      "id": "provenance-labels",
      "title": "Provenance Labels",
      "rule": "Use one explicit source label per entry: Platform shared, 1EdTech pass-through, Module gap fill, Alpha cut, Alpha restriction, Alpha rename, or Alpha extension. Divergences must link to the ITD that authorizes them.",
      "why": "Future modules need to know whether a value came from a standard, a platform gap fill, or an Alpha-facing change.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-014-data-dictionary-provenance"
    },
    {
      "id": "allowed-values",
      "title": "Allowed Values",
      "rule": "Every enum-like field links to a named allowed-value set. Each value needs behavior, useWhen, and invalidWhen text. A bare list of codes is not enough.",
      "why": "Allowed values are where invalid database state hides; behavior per value makes lifecycle bugs visible.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-014-data-dictionary-provenance"
    },
    {
      "id": "invalid-values",
      "title": "Invalid-Value Identification",
      "rule": "Fields that store IDs, references, enums, JSON, learner data, request hashes, Problem details, logs, or redacted metadata must name invalid examples directly.",
      "why": "The brainlift requires a dictionary that makes invalid or misaligned database values easy to identify.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-014-data-dictionary-provenance"
    },
    {
      "id": "relationships-cardinality",
      "title": "Relationships And Cardinality",
      "rule": "Relationship text must name the related table/object, cardinality, and nullability. Example: Many platform.audit_log rows may reference one platform.idempotency_key row; the reference is nullable.",
      "why": "Engineers writing joins need more than a column name that ends in _id.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-014-data-dictionary-provenance"
    },
    {
      "id": "anchors-canonical-paths",
      "title": "Anchors And Canonical Paths",
      "rule": "Table anchors use table-platform-tenant. Field anchors use field-platform-tenant-tenant-id. Never change an anchor after approval unless a rollback or redirect plan is documented.",
      "why": "Architecture, customer sites, implementation tests, and future module docs need stable deep links.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-011-hosted-docs-identity"
    },
    {
      "id": "dictionary-derived-ddl",
      "title": "Dictionary-Derived DDL",
      "rule": "Migrations must preserve dictionary table names, field names, SQL types, required/nullability, defaults, unique scopes, foreign keys, check constraints, indexes, and SQL comments. Implementation tests must fail when a published table, field, enum, or critical index is missing.",
      "why": "The database is shared product truth; implementation cannot quietly diverge from the approved dictionary.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-017-migrations-and-ddl-discipline"
    },
    {
      "id": "module-release-state",
      "title": "Module Release State",
      "rule": "Treat module_key as stable identity only. Any customer-facing module registry, module picker, or docs sentence that says whether a surface is approved must derive status from loop/<module>/state.json and use module_release_status.",
      "why": "A cold integrator must not be routed to a surface the loop has withdrawn for platform-contract reconciliation.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-013-loop-execution-durable-state"
    },
    {
      "id": "privacy-redaction",
      "title": "Privacy And Redaction",
      "rule": "No shared platform.* field may store Bearer tokens, auth headers, Cognito access/ID/refresh tokens, IP addresses, user agents, raw package bytes, student names, parent names, emails, phone numbers, SIS IDs, or other direct learner/parent PII. The single PITD-005 identity exception is platform.end_user_identity_binding.subject: it stores the exact opaque Cognito sub needed for deterministic operator binding and revocation; audit subjects and issued JWT subjects remain hashed/pseudonymous.",
      "why": "QTI's approved privacy pattern is now platform-wide student-data policy.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
    },
    {
      "id": "student-login-token-exchange",
      "title": "Student Login Token Exchange",
      "rule": "For every explicitly allowlisted active tenant, Platform3 owns the first-party Cognito Hosted UI code+PKCE login and opaque session. PLATFORM_TIMEBACK_TENANT_ROUTES_JSON is a strict array compiled to a map from canonical tenant UUID to exactly one redirect/post-login/logout tuple; all three URIs share one HTTPS origin and the callback contains that UUID. Duplicate, malformed, mismatched, or unlisted entries fail closed before storage. Host and Origin validate the selected tuple; neither chooses it. Each app uses a same-origin reverse proxy for only its exact auth paths, keeping the opaque cookie host-only and SameSite without an app-held secret or cross-site cookie. The legacy single redirect/post-login/logout variables retain their exact behavior only when this allowlist is absent. After the legacy operator invite returns a subject, an operator Bearer request binds exact issuer + subject + canonical Platform tenant UUID + People & Orgs person_id; there is no email auto-binding. The cookie is 30-minute idle/2-hour absolute and authorizes only session-token/logout. The auth route, binding, session, and audit stay on canonical platform.tenant.tenant_id. Every session-token request re-reads People & Orgs, loads that tenant row, then mints a 600-second HS256 Bearer JWT with its existing unique tenant_key in both tenantId and tenant_id and no aud because People & Orgs and Results already route and store by tenant key. A consumer that cannot safely hold that HS256 key POSTs the opaque JWT as Bearer to /platform/tenants/{canonicalTenantUuid}/token-context. The verifier requires both raw tenant aliases to be present and exactly equal the active row's tenant_key; rejects workspace aliases; validates raw unique nonempty roles/scopes before normalization; requires scalar role to equal roles[0], the exact people_orgs:read plus results:read scope set, integer exp-iat of exactly 600 seconds, exact person-scope union, and relationship-role provenance; and rejects unknown, container-grant, or extra privilege claims. It returns only the published no-store end-user response without echoing the token. The published matrix distinguishes invalid authentication (401), canonical-route validation (400), tenant/workspace mismatch (403 tenant_scope_mismatch), end-user contract or inactive-tenant denial (403 forbidden), unknown tenant (404), and wrong method (405). This bounded handoff adds no universal repository adapter, additional claim, second mapping authority, key distributor, or second identity service. Cognito tokens are discarded, no refresh vault exists, and all customer APIs remain Bearer-only.",
      "why": "Cognito owns credential verification, People & Orgs owns current identity/relationships, Platform owns each canonical-tenant binding/session/revocation path, and the strict route allowlist lets multiple first-party apps share one deployment without creating a Host authority, cross-site cookie, or second data mapping.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
    },
    {
      "id": "student-token-claims",
      "title": "Student End-User JWT Claims",
      "rule": "TimeBack end-user JWTs include only personId, studentId, agentOf, personIds, authProvider, and the exact Results compatibility aliases studentIds, guardianOf, and guideOf. Compatibility aliases repeat only the same authorized student ids; personIds never contains a parent or guide actor and does not add scope. The bridge does not emit placeIds, schoolIds, or classIds because People & Orgs interprets those as container-wide grants. Claims are re-derived on every token mint from a real, enabled, non-deleted, lifecycle-current person and active dated memberships. Guardian/parent agentOf and guardianOf come only from inverse OneRoster family_or_agent_person_ids on eligible students. Guide student scope requires the guide's current named class membership and matching current guide-to-student rows. If those relationships resolve to no eligible student, token minting fails closed. Claims are opaque ids, never names, emails, phone numbers, passwords, access tokens, or SIS identifiers. Audit rows store claim keys, counts, and hashes only.",
      "why": "The API and raw-DB/audit paths must agree on what identity was authorized without copying learner PII into shared platform.* fields or forcing modules to parse app-specific token shapes.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
    },
    {
      "id": "student-administrator-role",
      "title": "Student Administrator Role Modifier",
      "rule": "administrator is the only canonical privileged end-user role literal. Platform emits it only after the same current tenant-scoped People & Orgs person has both an active student membership and an active administrator place membership. student remains role and roles[0]. Administrator-only, class-only administrator membership, admin aliases, case variants, raw Cognito groups, stale or wrong-person rows, and container claims fail closed. The modifier adds no person, place, school, class, guardian, guide, or agent scope. A consumer must first verify exact current course enrollment from its server-owned roster before administrator may change that enrolled learner's sequencing.",
      "why": "Ilma's AP and Reading launch need one interoperable role literal without turning a place membership, identity-provider group, or consumer configuration into broad authorization.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
    },
    {
      "id": "producer-credential-provisioning",
      "title": "Producer Self-Service Credential Provisioning",
      "rule": "A producer obtains scoped, tenant-bound, auditable credentials (author:content, publish:content, read:content) through an authenticated API, never a ticket. Onboarding is the single operator act: an operator-authorized Bearer request (operator role or platform:credential:grant scope; a producer credential is refused) creates one active platform.producer_credential_grant per tenant + producer, enumerating exactly the grantable scope subset, the service role class, a 60..3600-second max TTL, and a bounded hourly issuance rate. After that, POST /platform/tenants/{canonicalTenantUuid}/producer-credentials is fully self-service: an already-tenant-authenticated principal whose exact subject the envelope binds mints or rotates short-lived credentials for ITS OWN tenant only — the tenant binding is enforced server-side against the tenant claim with no service-role bypass, and requested scopes/roles/TTL must sit inside the envelope or the request fails closed with an authz_denied audit row. Issued credentials are ordinary platform HS256 JWTs signed by the existing platform-jwt machinery (no new crypto) carrying the tenant's unique tenant_key in both tenantId and tenant_id — the same key-claim rule as the student login token exchange, and for the public demo tenant that key is demo — plus credential_id and grant_id provenance claims that token-exchange callers cannot forge. Every issuance inserts an append-only platform.producer_credential ledger row storing only the JWT's SHA-256 fingerprint and writes a platform.audit_log row joined by credential_id; the raw token appears only in the no-store mint response and is never persisted, logged, or audited. Revocation works and is fail-closed: revoking a credential (self-revoke by its own subject, or an operator) or its grant (operator; cascades to all outstanding credentials) immediately blocks minting and rotation at the platform routes, and offline verifiers converge within the bounded remaining TTL, which max_ttl_seconds caps at one hour. Exceeding the envelope's issuance rate returns the documented 429 rate_limited Problem. Consumer modules keep their existing verification unchanged: Content's recipe-content-publication publish:content requirement is satisfied by a credential minted here, and the recipe's 'requests credential provisioning through Platform tenant onboarding' sentence now resolves to this API instead of a human.",
      "why": "Owner ruling 2026-08-10 (#2794): producers must create, publish, and attach content entirely through authenticated APIs; #2727 showed the human provisioning step blocking a customer mid-ingest. The grant envelope keeps self-service from becoming self-escalation.",
      "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
    }
  ],
  "guardrailRules": [
    {
      "id": "gr-tenant-scope",
      "title": "1. Tenant scope -- always filter tenant_id from the JWT",
      "rule": "Every platform read is scoped to the caller's tenant. The API resolves tenant_id from the authenticated JWT tenantId (or tenant_id) claim and enforces it through assertTenantScope before any row is returned; a tenantId value supplied in the URL or query string is matched against the claim, never trusted on its own. GET /platform/tenants/{id} returns 404/scope-mismatch unless the path tenant equals the principal tenant (or the caller is a service/support/reviewer principal).",
      "why": "tenant_id is the platform isolation boundary. platform.idempotency_key and platform.audit_log are shared across every tenant and module, so an unscoped read mixes tenants. The repository hard-codes `where tenant_id = $1` on getTenant, listAuditLogs, and findIdempotencyKey for exactly this reason.",
      "raw": "Add `where tenant_id = $tenant` to EVERY query against platform.tenant, platform.idempotency_key, and platform.audit_log, and to every JOIN's ON clause (e.g. `on a.tenant_id = k.tenant_id` when joining audit_log to idempotency_key). Resolve $tenant from the same identity the API uses (the JWT tenantId claim); never take it from a request-supplied parameter without checking it against that claim.",
      "itds": [
        {
          "id": "PITD-003",
          "title": "Shared Tenant Model",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
        },
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        }
      ]
    },
    {
      "id": "gr-authz-precondition",
      "title": "2. Authorization precondition -- gate by role/scope before returning rows",
      "rule": "Reading these rows through the API is not just tenant-scoped; it is role/scope-gated. Audit-log reads require one of service, support, auditor, demo, reviewer (or scope platform:audit:read / platform:*). Idempotency-key inspection requires writer, support, service, demo, reviewer (or platform:idempotency:read / platform:*). Tenant creation requires service, writer, demo, reviewer (or platform:tenant:create / platform:*); creating directly in active requires the exact platform-operator tenant principal, service role, and platform:tenant:create or platform:* scope, while every other create authority remains provisioning-only. A caller without the authority gets a typed 403, not data.",
      "why": "platform.audit_log and platform.idempotency_key carry privileged operational history. The API never exposes them to a tenant-scoped principal that lacks the audit/idempotency authority. A raw SELECT bypasses authorization entirely, so the same tenant's rows become readable by a principal the API would have rejected -- a wrong-but-plausible 'the API would have shown me this' answer.",
      "raw": "Before returning any platform.audit_log or platform.idempotency_key row from the raw path, apply the same role/scope precondition the API checks: confirm the acting principal holds an audit-read (for audit_log) or idempotency-read (for idempotency_key) role or scope. If it does not, return the typed 403 the API would have returned -- do not return rows just because they are in the caller's tenant.",
      "itds": [
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ]
    },
    {
      "id": "gr-scope-tuple",
      "title": "3. Idempotency scope -- apply the owning route profile",
      "rule": "The default idempotency record is identified by (tenant_id, module, surface, method, route_template, operation_id, idempotency_key). An explicit Platform-owned route profile may be stricter: CASE 1EdTech resolves on (tenant_id, module=case, surface=1edtech, idempotency_key), with method/route/operation/resource/body/If-Match differences becoming hash conflicts under that row. No profile ever keys on idempotency_key without tenant and module/surface.",
      "why": "The same client-chosen Idempotency-Key legitimately recurs across tenants and modules, while CASE deliberately forbids reusing it across CASE operations in one tenant. A generic key-only query leaks tenants; a generic seven-column CASE query misses the partial-unique winner and can imply a second mutation is allowed.",
      "raw": "First pin tenant_id, module, and surface. Use the seven-column tuple for the shared default. For module=case and surface=1edtech, query `where tenant_id=$t and module='case' and surface='1edtech' and idempotency_key=$key`, then compare canonical_request_hash and the retained method/route/operation identity. Never query idempotency_key without tenant/module/surface and never ignore a documented partial unique profile.",
      "itds": [
        {
          "id": "PITD-007",
          "title": "Idempotency And Optimistic Concurrency",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-007-idempotency-and-concurrency"
        },
        {
          "id": "PITD-002",
          "title": "Module Schemas And Shared Platform Schema",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-002-module-schema-boundaries"
        }
      ]
    },
    {
      "id": "gr-module-surface-scope",
      "title": "4. Module / surface scope -- pin the right partition of the shared table",
      "rule": "platform.idempotency_key and platform.audit_log are single physical tables shared by every documented writer module (platform, incept, qti, oneroster, caliper, case, nweamap, ed_fi, people_and_orgs, curriculum, content, events, results, analytics) and every surface (platform, 1edtech, alpha), partitioned only by the module and surface columns. An API endpoint only ever reads the module/surface it serves; it never returns another module's rows.",
      "why": "Reading platform.audit_log or platform.idempotency_key without pinning module (and usually surface) returns every module's operational rows at once -- QTI rows mixed with OneRoster rows mixed with platform rows -- which no endpoint ever returns. Counting 'platform writes' over an unfiltered audit_log silently includes every other module.",
      "raw": "When answering a per-module/per-surface question, add `and module = '<module>'` (and `and surface = '<surface>'` where the endpoint is surface-specific) to the query. Do not union modules or surfaces unless you are deliberately answering a cross-module question; the API never does so implicitly.",
      "itds": [
        {
          "id": "PITD-002",
          "title": "Module Schemas And Shared Platform Schema",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-002-module-schema-boundaries"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ]
    },
    {
      "id": "gr-tenant-status",
      "title": "5. Tenant lifecycle status -- a row in platform.tenant is not always live",
      "rule": "platform.tenant.status moves through provisioning -> active -> suspended -> archived. Create defaults to provisioning; the existing idempotent create may start active only when authentication and operational setup are complete and the caller is the exact platform-operator tenant principal with Platform service role plus platform:tenant:create or platform:* scope. A tenant row existing is not the same as the tenant being live: provisioning has not finished onboarding, suspended is access-revoked, and archived is retired. The status column is the authoritative lifecycle signal.",
      "why": "A raw `select * from platform.tenant` (or a join that assumes every tenant_id is a usable tenant) treats suspended and archived tenants as active, inflating 'active tenant' counts and routing work to tenants the platform considers not live. status is a read-time filter, not a row deletion -- archived rows are retained for history and audit.",
      "raw": "For the 'live/active tenants' answer add `and status = 'active'`. To ask 'still onboarding' use status = 'provisioning'; for access-revoked use 'suspended'; for retired use 'archived'. Never infer liveness from row existence alone, and never silently include non-active tenants in a 'current tenants' count.",
      "itds": [
        {
          "id": "PITD-003",
          "title": "Shared Tenant Model",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
        },
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        }
      ]
    },
    {
      "id": "gr-demo-tenant-split",
      "title": "6. Demo-tenant split -- demo_* tenants do not live in Postgres",
      "rule": "Tenant ids beginning with demo_ are stateless, signed, in-memory demo tenants served by the demo repository, not by platform.* in Postgres. Real tenants are UUIDs; the repository routes demo_* reads/writes away from the database and rejects any non-UUID tenant id against Postgres as not-found (assertPostgresTenantId).",
      "why": "A raw Postgres query for a demo_* tenant returns zero rows even though the API answers successfully from the demo repository -- a false 'tenant/audit/idempotency does not exist' answer. Conversely, treating a UUID demo placeholder as a real Postgres row is equally wrong.",
      "raw": "Detect demo_* tenant ids before querying Postgres: if `$tenant like 'demo_%'`, the answer comes from the stateless demo path, not from platform.* tables -- do not conclude 'not found' from an empty Postgres result. Only run the platform.* SQL above for UUID-shaped real tenant ids.",
      "itds": [
        {
          "id": "PITD-003",
          "title": "Shared Tenant Model",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-003-shared-tenant-model"
        },
        {
          "id": "PITD-005",
          "title": "Authentication, Authorization, And Tenant Scope",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-005-auth-tenant-scope"
        }
      ]
    },
    {
      "id": "gr-audit-ordering-limit",
      "title": "7. Audit-log read grain -- newest-first, bounded page size",
      "rule": "The audit-log list endpoint returns rows for one tenant ordered by occurred_at descending, with a page size that defaults to 20 and is clamped to the range 1..100. The API never returns an unbounded or arbitrarily ordered audit stream.",
      "why": "A raw `select * from platform.audit_log where tenant_id = $t` with no ORDER BY and no LIMIT returns rows in physical/undefined order and without the cap, so a consumer comparing 'the latest N audit events' against the API gets a different set and a different order.",
      "raw": "Match the API shape: `... where tenant_id = $t [and module=$m] order by occurred_at desc limit greatest(1, least($limit, 100))` with $limit defaulting to 20. Apply the same descending occurred_at ordering and 1..100 clamp the API applies.",
      "itds": [
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        },
        {
          "id": "PITD-010",
          "title": "Observability, Metrics, And SLOs",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-010-observability-and-slos"
        }
      ]
    },
    {
      "id": "gr-pii-redaction",
      "title": "8. Redaction grain -- treat metadata columns as already PII-free, do not re-expand",
      "rule": "platform.tenant.metadata and platform.audit_log.redacted_metadata hold only safe counts, hashes, and summaries by contract -- no direct learner/parent PII, credentials, raw tokens, IP addresses, or user agents. actor_subject is a pseudonymous principal id, not a person's name. The API relies on this and never re-hydrates PII into a response.",
      "why": "A raw reader that joins audit_log.resource_id or actor_subject back out to a module's PII tables (or that mines metadata expecting personal data) produces a record the API would never emit, leaking PII through the raw-DB path and diverging from the API answer.",
      "raw": "Read metadata / redacted_metadata as already-redacted summaries; do not join them or resource_id/actor_subject back to learner/parent PII to 'enrich' a result. The API's answer contains only the redacted shape -- the raw path must return the same redacted shape, not a re-expanded one.",
      "itds": [
        {
          "id": "PITD-008",
          "title": "Student Data Privacy And PII Handling",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-008-privacy-pii-student-data"
        },
        {
          "id": "PITD-009",
          "title": "Cross-Module Audit Log",
          "href": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-009-audit-log"
        }
      ]
    }
  ],
  "moduleReleaseStates": [
    {
      "moduleKey": "platform",
      "surface": "1edtech",
      "releaseStatus": "approved",
      "loopEvidence": "Platform 1EdTech is being re-delivered from this data dictionary. The approved architecture remains upstream truth; downstream customer/API/QC/integration routing is withheld during the cascade, even if older deploy URLs still resolve. Build-time source: loop/platform/state.json, generated 2026-08-10T12:39:23Z; regenerate this site rather than copying this row as permanent release truth.",
      "registryRule": "Advertise Platform 1EdTech as approved. Keep deriving that routing from loop/platform/state.json; if any required deliverable leaves approved, regenerate the registry before publishing."
    },
    {
      "moduleKey": "qti",
      "surface": "1edtech",
      "releaseStatus": "approved",
      "loopEvidence": "Build-time derivation from loop/qti/state.json: approved deliverables are architecture, data_dictionary, customer_website, implementation, surface_qc, integration, skill_pack; not release-approved for registry routing are none. Regenerate this site to refresh the dated snapshot.",
      "registryRule": "Advertise QTI 1EdTech as approved. Keep deriving that routing from loop/qti/state.json; if any required deliverable leaves approved, regenerate the registry before publishing."
    },
    {
      "moduleKey": "qti",
      "surface": "alpha",
      "releaseStatus": "approved",
      "loopEvidence": "Build-time derivation from loop/qti/state.json: approved deliverables are architecture, data_dictionary, customer_website, implementation, surface_qc; not release-approved for registry routing are none. Regenerate this site to refresh the dated snapshot.",
      "registryRule": "Advertise QTI Alpha as approved. Keep deriving that routing from loop/qti/state.json; if any required deliverable leaves approved, regenerate the registry before publishing."
    },
    {
      "moduleKey": "oneroster",
      "surface": "1edtech",
      "releaseStatus": "approved",
      "loopEvidence": "Build-time derivation from loop/oneroster/state.json: approved deliverables are architecture, data_dictionary, customer_website, implementation, surface_qc, integration, skill_pack; not release-approved for registry routing are none. Regenerate this site to refresh the dated snapshot.",
      "registryRule": "Advertise OneRoster 1EdTech as approved. Keep deriving that routing from loop/oneroster/state.json; if any required deliverable leaves approved, regenerate the registry before publishing."
    },
    {
      "moduleKey": "caliper",
      "surface": "1edtech",
      "releaseStatus": "approved",
      "loopEvidence": "Build-time derivation from loop/caliper/state.json: approved deliverables are architecture, data_dictionary, customer_website, implementation, surface_qc, integration, skill_pack; not release-approved for registry routing are none. Regenerate this site to refresh the dated snapshot.",
      "registryRule": "Advertise Caliper 1EdTech as approved. Keep deriving that routing from loop/caliper/state.json; if any required deliverable leaves approved, regenerate the registry before publishing."
    },
    {
      "moduleKey": "case",
      "surface": "1edtech",
      "releaseStatus": "approved",
      "loopEvidence": "Build-time derivation from loop/case/state.json: approved deliverables are architecture, data_dictionary, customer_website, implementation, surface_qc, integration, skill_pack; not release-approved for registry routing are none. Regenerate this site to refresh the dated snapshot.",
      "registryRule": "Advertise CASE 1EdTech as approved. Keep deriving that routing from loop/case/state.json; if any required deliverable leaves approved, regenerate the registry before publishing."
    }
  ],
  "qtiReconciliations": [
    {
      "source": "qti.tenant",
      "platformTruth": "platform.tenant",
      "decision": "The shared tenant row is platform.tenant. QTI's existing qti.tenant table is the predecessor pattern, not the future cross-module tenant authority.",
      "implementationRequirement": "The platform implementation deliverable must migrate qti.tenant rows or provide a compatibility view before future modules rely on platform.tenant for QTI joins.",
      "rollbackSignal": "If QTI docs or implementation continue to claim qti.tenant is the platform-wide tenant truth after the bridge exists, rollback to the earliest QTI artifact that makes that claim."
    },
    {
      "source": "qti.content_package.idempotency_key",
      "platformTruth": "platform.idempotency_key",
      "decision": "The shared retry ledger is platform.idempotency_key. QTI package rows may keep a package-specific copy or later link to the ledger, but replay/conflict semantics are platform-owned.",
      "implementationRequirement": "Shared middleware must populate platform.idempotency_key for QTI retryable operations and keep any qti.content_package copy consistent.",
      "rollbackSignal": "If QTI continues to implement replay/conflict behavior only in qti.content_package without the platform ledger, rollback to QTI implementation or customer website as appropriate."
    },
    {
      "source": "QTI lacks a shared audit table",
      "platformTruth": "platform.audit_log",
      "decision": "High-risk QTI operations become audit emitters once the platform shared library exists.",
      "implementationRequirement": "QTI import, authoring save, delivery runtime deletion, service-role maintenance, conformance mutation, trust change, and authorization denial paths must write platform.audit_log rows.",
      "rollbackSignal": "If a future QTI customer website promises auditability that the implementation does not emit, rollback to QTI implementation or customer website."
    },
    {
      "source": "QTI hardcoded demo/reviewer aliases and unnamed artifact-version lists",
      "platformTruth": "platform.tenant plus tenant-owned qti.artifact_collection manifests",
      "decision": "Every service principal binds to one platform.tenant row. Content and CASE credentials carry that row's tenant_key because those APIs route by key; QTI credentials carry the same row's tenant_id UUID because QTI storage and routes are UUID-owned. The public human alias demo resolves platform.tenant.tenant_key=demo; an explicit historical UUID can remain a compatibility target but cannot capture the alias or strand new package data outside the shared demo tenant. Those are identifiers for one tenant, not permission to remap a consumer tenant. A named QTI collection is immutable, belongs to exactly one tenant, lists ordered exact artifact versions, and publishes Content aliases that preserve QTI native identity (content_id=artifact_id and content_version_id=artifact_version_id). The governed timeback-alphatest-legacy-forms-v1 collection is valid only with exactly 17 unique form versions.",
      "implementationRequirement": "Provision separate least-privilege Content, CASE, and QTI JWTs for the same platform.tenant; resolve tenant keys through platform.tenant before any legacy fallback; enforce operation scopes and exact QTI UUID route-token equality; remove reviewer-to-demo compatibility access; import complete source packages through the Content QTI seam into the target tenant; then publish and read back the immutable 17-member target collection. Never persist credentials in a collection or audit row.",
      "rollbackSignal": "If a service token can cross to demo, a collection member belongs to another tenant, a Content alias changes native QTI identity, or the named legacy collection has other than 17 exact members, rollback to the QTI/Content implementation that introduced the divergence."
    },
    {
      "source": "QTI assessment-item-ref href/identifier without native member identity or governed learning projection",
      "platformTruth": "qti.artifact.imported_version_id plus alpha.content_kc_tag plus alpha.standard_kc_map",
      "decision": "An ordered QTI package ref resolves within its owning package to the immutable version created at import, never mutable latest_version_id or a global identifier search. Content remains the sole owner of item-to-KC attribution and Curriculum remains the sole owner of KC-to-CASE-standard mapping. QTI delivery JSON may read-project those same-tenant governed GUIDs beside the native member identity; it does not store or infer learning facts.",
      "implementationRequirement": "Persist imported_version_id for every package artifact; enrich a matching qti-assessment-item-ref with artifactId, artifactVersionId, sorted knowledgeComponentGuids, and sorted caseStandardGuids by exact same-package href+identifier. Missing tags remain empty so adaptive consumers fail closed. Write missing mappings only through Content POST /kc-tags with provenance, confidence, a dry-run diff, and read-back.",
      "rollbackSignal": "If an old package changes member identity after authoring, a member resolves outside its package or tenant, QTI stores a duplicate KC/standard fact, or a projection is inferred from XML/title/identifier search, rollback to the QTI implementation or Content mapping input that introduced the divergence."
    },
    {
      "source": "qti/1edtech release status",
      "platformTruth": "module_release_status derived from loop/qti/state.json",
      "decision": "module_key=qti remains the stable namespace for QTI-owned records, and qti/1edtech release status is a loop-derived surface status rather than prose copied into downstream docs. At this generation, loop/qti/state.json lists every required QTI 1EdTech deliverable as approved, so qti/1edtech is approved.",
      "implementationRequirement": "The Platform customer website and /platform/modules implementation must expose per-surface release status from loop-derived module_release_status. For the current QTI 1EdTech state they must mark qti/1edtech approved and may cite the approved architecture, data_dictionary, customer_website, implementation, surface_qc, integration, and skill_pack artifacts. If an older rolled-back Platform API deployment still returns qti/1edtech as under_reconciliation, treat that as a downstream implementation artifact that failed to inherit this dictionary, not as source authority.",
      "rollbackSignal": "If Platform docs or API responses disagree with loop/qti/state.json about qti/1edtech release status, rollback to Platform data_dictionary for status semantics or to the downstream Platform artifact that failed to inherit them."
    }
  ],
  "inceptProducerSurface": {
    "checkedAt": "2026-06-25T23:03:53.409Z",
    "objectCount": 18,
    "fieldCount": 392,
    "tableCount": 11,
    "viewCount": 7,
    "objects": [
      {
        "name": "incept.incept_event_ledger",
        "relationName": "incept_event_ledger",
        "title": "Event Ledger",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Append-only canonical ledger for Incept loop events in the shared Platform3 Supabase/Postgres database. Generated JSON reports are projections from this stream.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(event_id)",
        "relationships": [
          "causation_event_id references incept.incept_event_ledger.event_id.",
          "platform_audit_log_id references platform.audit_log.audit_log_id.",
          "platform_idempotency_key_id references platform.idempotency_key.idempotency_key_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "CHECK: CHECK (length(btrim(actor_type)) > 0 AND length(btrim(actor_subject)) > 0)",
          "FOREIGN KEY: FOREIGN KEY (causation_event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (event_type ~ '^[a-z][a-z0-9_.-]{1,159}$'::text)",
          "CHECK: CHECK (length(btrim(idempotency_key)) >= 1 AND length(btrim(idempotency_key)) <= 200)",
          "UNIQUE: UNIQUE (idempotency_key)",
          "CHECK: CHECK (jsonb_typeof(redacted_metadata) = 'object'::text)",
          "CHECK: CHECK (module_key = 'incept'::text)",
          "CHECK: CHECK (payload_hash IS NULL OR payload_hash ~ '^sha256:[0-9a-f]{64}$'::text)",
          "CHECK: CHECK (jsonb_typeof(payload) = 'object'::text)",
          "PRIMARY KEY: PRIMARY KEY (event_id)",
          "FOREIGN KEY: FOREIGN KEY (platform_audit_log_id) REFERENCES platform.audit_log(audit_log_id)",
          "FOREIGN KEY: FOREIGN KEY (platform_idempotency_key_id) REFERENCES platform.idempotency_key(idempotency_key_id)",
          "CHECK: CHECK (surface = ANY (ARRAY['platform'::text, '1edtech'::text, 'alpha'::text, 'incept'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_event_ledger_correlation_idx ON incept.incept_event_ledger USING btree (correlation_id, occurred_at DESC)",
          "CREATE UNIQUE INDEX incept_event_ledger_idempotency_key_key ON incept.incept_event_ledger USING btree (idempotency_key)",
          "CREATE UNIQUE INDEX incept_event_ledger_idempotency_uidx ON incept.incept_event_ledger USING btree (idempotency_key)",
          "CREATE INDEX incept_event_ledger_loop_idx ON incept.incept_event_ledger USING btree (loop_id, occurred_at DESC)",
          "CREATE INDEX incept_event_ledger_payload_gin_idx ON incept.incept_event_ledger USING gin (payload)",
          "CREATE UNIQUE INDEX incept_event_ledger_pkey ON incept.incept_event_ledger USING btree (event_id)",
          "CREATE INDEX incept_event_ledger_recorded_idx ON incept.incept_event_ledger USING btree (recorded_at, event_id)",
          "CREATE INDEX incept_event_ledger_skill_idx ON incept.incept_event_ledger USING btree (skill_id, occurred_at DESC)",
          "CREATE INDEX incept_event_ledger_source_path_idx ON incept.incept_event_ledger USING btree (source_path)",
          "CREATE INDEX incept_event_ledger_type_time_idx ON incept.incept_event_ledger USING btree (event_type, occurred_at DESC)"
        ],
        "projectionRules": [
          "Append-only canonical Incept fact stream. Typed index tables and views are projections from this stream.",
          "Incept producer events carry trafficClass in payload using incept_traffic_class values. Platform3 API readback also accepts legacy traffic_class payload spelling and defaults missing legacy rows to customer for compatibility.",
          "Generated student-facing artifacts referenced by payload or artifact rows must materialize as canonical Content/QTI rows or explicit reconciliation errors.",
          "Direct app reads from this table are deprecated bootstrap only; product reads go through Platform3-native API/view paths with tenant scope and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select event_id, event_type, occurred_at, payload_hash from incept.incept_event_ledger where tenant_id = $1 order by occurred_at desc limit 50;",
        "fields": [
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": "gen_random_uuid()",
            "key": "Primary key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. Default: gen_random_uuid(). FOREIGN KEY: FOREIGN KEY (causation_event_id) REFERENCES incept.incept_event_ledger(event_id). PRIMARY KEY: PRIMARY KEY (event_id).",
            "allowedValues": null,
            "relationship": "Primary event identity for the canonical ledger.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_event_ledger rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-tenant-id"
          },
          {
            "name": "platform_audit_log_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Optional link to platform.audit_log for the cross-module redacted audit narrative.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (platform_audit_log_id) REFERENCES platform.audit_log(audit_log_id).",
            "allowedValues": null,
            "relationship": "Many incept_event_ledger rows reference one platform.audit_log.audit_log_id; nullable=true.",
            "example": "0b7d63b5-e670-42fb-bac0-a821fd0626c0",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-platform-audit-log-id"
          },
          {
            "name": "platform_idempotency_key_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Optional link to platform.idempotency_key for HTTP/API writers once the Platform module admits incept as an idempotency module.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (platform_idempotency_key_id) REFERENCES platform.idempotency_key(idempotency_key_id).",
            "allowedValues": null,
            "relationship": "Many incept_event_ledger rows reference one platform.idempotency_key.idempotency_key_id; nullable=true.",
            "example": "8535685a-8730-4c61-9226-581f0370bd37",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-platform-idempotency-key-id"
          },
          {
            "name": "module_key",
            "type": "text",
            "required": true,
            "default": "'incept'::text",
            "key": "Field",
            "meaning": "Writer namespace. For Incept ledger rows this must be incept, which records producer attribution without making Incept a consumer-facing model.",
            "constraints": "Required text column. Default: 'incept'::text. CHECK: CHECK (module_key = 'incept'::text).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "incept",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-module-key"
          },
          {
            "name": "surface",
            "type": "text",
            "required": true,
            "default": "'platform'::text",
            "key": "Field",
            "meaning": "Surface or producer path that emitted the fact. The incept value is a producer-writer identity, not a third consumer API surface.",
            "constraints": "Required text column. Default: 'platform'::text. CHECK: CHECK (surface = ANY (ARRAY['platform'::text, '1edtech'::text, 'alpha'::text, 'incept'::text])). Allowed values: platform means Platform3 substrate path; 1edtech means expert standards surface path; alpha means plain-language Alpha path; incept means governed producer-writer path.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "incept",
            "invalidWhen": "null; outside allowed values: platform means Platform3 substrate path; 1edtech means expert standards surface path; alpha means plain-language Alpha path; incept means governed producer-writer path.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-surface"
          },
          {
            "name": "event_type",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Governed event label that names what happened in the generation loop.",
            "constraints": "Required text column. CHECK: CHECK (event_type ~ '^[a-z][a-z0-9_.-]{1,159}$'::text).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "incept.producer_surface.registered",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-event-type"
          },
          {
            "name": "event_schema_version",
            "type": "integer(32)",
            "required": true,
            "default": "1",
            "key": "Field",
            "meaning": "Version of the payload contract used by this event.",
            "constraints": "Required integer(32) column. Default: 1.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-event-schema-version"
          },
          {
            "name": "idempotency_key",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Deterministic writer-supplied key. Duplicate inserts must reuse the existing event instead of creating a second canonical fact.",
            "constraints": "Required text column. CHECK: CHECK (length(btrim(idempotency_key)) >= 1 AND length(btrim(idempotency_key)) <= 200). UNIQUE: UNIQUE (idempotency_key). FOREIGN KEY: FOREIGN KEY (platform_idempotency_key_id) REFERENCES platform.idempotency_key(idempotency_key_id).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "incept-run-2026-06-25-001",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-idempotency-key"
          },
          {
            "name": "operation_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Stable operation name used for audit, idempotency, and support correlation.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "incept.producer_surface.register",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-operation-id"
          },
          {
            "name": "request_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Request-instance identifier returned to callers and used in support/debug correlation.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "req_20260625_148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-request-id"
          },
          {
            "name": "trace_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "End-to-end trace identifier shared with logs, Problems, and audit rows.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "trace_20260625_148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-trace-id"
          },
          {
            "name": "correlation_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Cross-event correlation key for related generation, repair, promotion, and deployment facts.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "corr-platform3-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-correlation-id"
          },
          {
            "name": "causation_event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Ledger event that caused this event.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (causation_event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_event_ledger rows reference one incept.incept_event_ledger.event_id; nullable=true.",
            "example": "f499f17f-7c3e-4aa8-8f6c-0bd98278dba7",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-causation-event-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-loop-run-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-skill-id"
          },
          {
            "name": "content_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Generated artifact type, such as lesson, question, script, or report component.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-content-type"
          },
          {
            "name": "content_subtype",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "More specific generated artifact subtype used for quality grids and model comparisons.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "mastery_gate_question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-content-subtype"
          },
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-quality-bar-version"
          },
          {
            "name": "artifact_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Generated or evaluated artifact identifier from the producer workflow.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "artifact-platform-dd-index-html",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-artifact-id"
          },
          {
            "name": "external_issue_key",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Stable external issue key that connects Platform3 evidence to GitHub or another tracker.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "GH-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-external-issue-key"
          },
          {
            "name": "actor_type",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Kind of actor that emitted or approved the fact, such as agent, human, system, or daemon.",
            "constraints": "Required text column. CHECK: CHECK (length(btrim(actor_type)) > 0 AND length(btrim(actor_subject)) > 0). CHECK: CHECK (length(btrim(actor_type)) > 0 AND length(btrim(actor_subject)) > 0).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "agent",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-actor-type"
          },
          {
            "name": "actor_subject",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Pseudonymous subject for the actor; do not store credentials, JWTs, or direct customer PII here.",
            "constraints": "Required text column. CHECK: CHECK (length(btrim(actor_type)) > 0 AND length(btrim(actor_subject)) > 0). CHECK: CHECK (length(btrim(actor_type)) > 0 AND length(btrim(actor_subject)) > 0).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "agent:codex:data-dictionary-doer",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-actor-subject"
          },
          {
            "name": "actor_agent_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Agent identifier when the actor is an AI or automated process.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "agent-codex-data-dictionary-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-actor-agent-id"
          },
          {
            "name": "actor_agent_model",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Model name or version for the AI agent that produced or judged the event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "gpt-5-codex-2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-actor-agent-model"
          },
          {
            "name": "repo_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository URL associated with the event or deployment evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-repo-url"
          },
          {
            "name": "branch_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Git branch associated with the event or deployment evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "platform3-148-incept-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-branch-name"
          },
          {
            "name": "base_branch",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Base branch used for comparison, PR, or landing evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "main",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-base-branch"
          },
          {
            "name": "commit_sha",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Git commit SHA tied to the event, repair, promotion, or deployment.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-commit-sha"
          },
          {
            "name": "worktree_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Local or agent worktree path recorded as evidence; it is diagnostic and not a durable product URL.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-worktree-path"
          },
          {
            "name": "pull_request_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Pull request URL linked to a repair, promotion, or deployment event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-pull-request-url"
          },
          {
            "name": "source_system",
            "type": "text",
            "required": true,
            "default": "'incept'::text",
            "key": "Field",
            "meaning": "System that produced the evidence, such as GitHub, Workflowy, agent runner, deployment provider, or local backfill.",
            "constraints": "Required text column. Default: 'incept'::text.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "github",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-source-system"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-source-url"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-source-path"
          },
          {
            "name": "occurred_at",
            "type": "timestamptz",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Time the underlying event happened.",
            "constraints": "Required timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-occurred-at"
          },
          {
            "name": "recorded_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Time Platform3 recorded the event.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-recorded-at"
          },
          {
            "name": "payload",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Typed event body. Keep direct credentials, JWTs, raw customer PII, IP addresses, and user agents out of this field.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (payload_hash IS NULL OR payload_hash ~ '^sha256:[0-9a-f]{64}$'::text). CHECK: CHECK (jsonb_typeof(payload) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-payload"
          },
          {
            "name": "payload_hash",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "sha256 hash proving the payload used by this row or projection.",
            "constraints": "Nullable text column. CHECK: CHECK (payload_hash IS NULL OR payload_hash ~ '^sha256:[0-9a-f]{64}$'::text).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-payload-hash"
          },
          {
            "name": "redacted_metadata",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Small redacted operational facts only: counts, hashes, timings, source paths, and summary labels.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(redacted_metadata) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-ledger-redacted-metadata"
          }
        ],
        "anchor": "table-incept-incept-event-ledger"
      },
      {
        "name": "incept.incept_loop_runs",
        "relationName": "incept_loop_runs",
        "title": "Loop Runs",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Durable run envelope for daemon, global, and per-loop executions. The event ledger remains the canonical fact stream; this table is the run index.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(loop_run_id)",
        "relationships": [
          "completed_event_id references incept.incept_event_ledger.event_id.",
          "started_event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (completed_event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "PRIMARY KEY: PRIMARY KEY (loop_run_id)",
          "CHECK: CHECK (scope = ANY (ARRAY['loop'::text, 'global'::text, 'daemon'::text, 'backfill'::text]))",
          "FOREIGN KEY: FOREIGN KEY (started_event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (status = ANY (ARRAY['queued'::text, 'running'::text, 'succeeded'::text, 'failed'::text, 'cancelled'::text, 'skipped'::text]))",
          "CHECK: CHECK (jsonb_typeof(summary) = 'object'::text)",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_loop_runs_event_config_idx ON incept.incept_loop_runs USING btree (event_config_id, started_at DESC)",
          "CREATE INDEX incept_loop_runs_loop_ids_gin_idx ON incept.incept_loop_runs USING gin (loop_ids)",
          "CREATE UNIQUE INDEX incept_loop_runs_pkey ON incept.incept_loop_runs USING btree (loop_run_id)",
          "CREATE INDEX incept_loop_runs_status_idx ON incept.incept_loop_runs USING btree (status, started_at DESC)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_loop_runs where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "loop_run_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (loop_run_id).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-loop-run-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_loop_runs rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-tenant-id"
          },
          {
            "name": "started_event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Ledger event that marks when this loop run started; null means the run envelope was backfilled or created before start-event linking was available.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (started_event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_loop_runs rows may reference one incept.incept_event_ledger.event_id as their start event; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-started-event-id"
          },
          {
            "name": "completed_event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Ledger event that records the terminal outcome for this loop run; null means the run is still open or ended before completion-event linking was available.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (completed_event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_loop_runs rows may reference one incept.incept_event_ledger.event_id as their completion event; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-completed-event-id"
          },
          {
            "name": "event_config_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Soft reference to the runner or daemon configuration that launched the run, used to compare runs started from the same schedule, prompt set, or operator profile.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to an Incept runner configuration outside this catalog snapshot; many loop runs may share one event_config_id; nullable=true.",
            "example": "event-config-platform3-nightly",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-event-config-id"
          },
          {
            "name": "trigger_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Named trigger that started the loop run, such as daemon schedule, manual operator run, issue triage, or backfill.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "manual_repair",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-trigger-name"
          },
          {
            "name": "scope",
            "type": "text",
            "required": true,
            "default": "'loop'::text",
            "key": "Field",
            "meaning": "Run scope for the Incept loop envelope. The table CHECK defines whether this is one loop, global work, daemon work, or backfill.",
            "constraints": "Required text column. Default: 'loop'::text. CHECK: CHECK (scope = ANY (ARRAY['loop'::text, 'global'::text, 'daemon'::text, 'backfill'::text])). Allowed values: loop means the run is scoped to one named generation loop or skill path; global means the run spans multiple loops or platform-wide Incept maintenance; daemon means the run was started by an automated recurring worker; backfill means the run is replaying or repairing historical Incept evidence.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop",
            "invalidWhen": "null; outside allowed values: loop means the run is scoped to one named generation loop or skill path; global means the run spans multiple loops or platform-wide Incept maintenance; daemon means the run was started by an automated recurring worker; backfill means the run is replaying or repairing historical Incept evidence.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-scope"
          },
          {
            "name": "loop_ids",
            "type": "text[]",
            "required": true,
            "default": "'{}'::text[]",
            "key": "Field",
            "meaning": "Array of loop identifiers included in a multi-loop, global, daemon, or backfill run.",
            "constraints": "Required text[] column. Default: '{}'::text[].",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{math,reading}",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-loop-ids"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": "'queued'::text",
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. Default: 'queued'::text. CHECK: CHECK (status = ANY (ARRAY['queued'::text, 'running'::text, 'succeeded'::text, 'failed'::text, 'cancelled'::text, 'skipped'::text])). Allowed values: queued means accepted but not started; running means actively executing; succeeded means completed successfully; failed means completed with an error; cancelled means intentionally stopped before completion; skipped means deliberately not run.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: queued means accepted but not started; running means actively executing; succeeded means completed successfully; failed means completed with an error; cancelled means intentionally stopped before completion; skipped means deliberately not run.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-status"
          },
          {
            "name": "started_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Time the run or repair attempt started.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-started-at"
          },
          {
            "name": "completed_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Time the run or repair attempt reached a terminal state.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-completed-at"
          },
          {
            "name": "actor_type",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Kind of actor that emitted or approved the fact, such as agent, human, system, or daemon.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "agent",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-actor-type"
          },
          {
            "name": "actor_subject",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Pseudonymous subject for the actor; do not store credentials, JWTs, or direct customer PII here.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "agent:codex:data-dictionary-doer",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-actor-subject"
          },
          {
            "name": "actor_agent_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Agent identifier when the actor is an AI or automated process.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "agent-codex-data-dictionary-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-actor-agent-id"
          },
          {
            "name": "actor_agent_model",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Model name or version for the AI agent that produced or judged the event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "gpt-5-codex-2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-actor-agent-model"
          },
          {
            "name": "repo_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository URL associated with the event or deployment evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-repo-url"
          },
          {
            "name": "branch_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Git branch associated with the event or deployment evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "platform3-148-incept-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-branch-name"
          },
          {
            "name": "base_branch",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Base branch used for comparison, PR, or landing evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "main",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-base-branch"
          },
          {
            "name": "commit_sha",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Git commit SHA tied to the event, repair, promotion, or deployment.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-commit-sha"
          },
          {
            "name": "worktree_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Local or agent worktree path recorded as evidence; it is diagnostic and not a durable product URL.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-worktree-path"
          },
          {
            "name": "command",
            "type": "text[]",
            "required": true,
            "default": "'{}'::text[]",
            "key": "Field",
            "meaning": "Command or agent invocation that started the run. It is diagnostic evidence, not an executable contract for consumers.",
            "constraints": "Required text[] column. Default: '{}'::text[].",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{math,reading}",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-command"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-source-url"
          },
          {
            "name": "summary",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted summary object used for reports and checkpoint evidence.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(summary) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-summary"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-created-at"
          },
          {
            "name": "updated_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was last updated.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-loop-runs-updated-at"
          }
        ],
        "anchor": "table-incept-incept-loop-runs"
      },
      {
        "name": "incept.incept_event_artifacts",
        "relationName": "incept_event_artifacts",
        "title": "Event Artifacts",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Pointers from ledger events to durable evidence: Supabase Storage objects, local JSON paths, GitHub URLs, Workflowy URLs, model outputs, screenshots, and generated artifacts.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(artifact_pointer_id)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "UNIQUE: UNIQUE (event_id, artifact_key)",
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL)",
          "CHECK: CHECK (jsonb_typeof(metadata) = 'object'::text)",
          "PRIMARY KEY: PRIMARY KEY (artifact_pointer_id)",
          "CHECK: CHECK (sha256 IS NULL OR sha256 ~ '^sha256:[0-9a-f]{64}$'::text)",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE UNIQUE INDEX incept_event_artifacts_event_id_artifact_key_key ON incept.incept_event_artifacts USING btree (event_id, artifact_key)",
          "CREATE INDEX incept_event_artifacts_event_idx ON incept.incept_event_artifacts USING btree (event_id)",
          "CREATE UNIQUE INDEX incept_event_artifacts_pkey ON incept.incept_event_artifacts USING btree (artifact_pointer_id)",
          "CREATE INDEX incept_event_artifacts_source_path_idx ON incept.incept_event_artifacts USING btree (source_path)",
          "CREATE INDEX incept_event_artifacts_storage_path_idx ON incept.incept_event_artifacts USING btree (storage_bucket, storage_path)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_event_artifacts where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "artifact_pointer_id",
            "type": "uuid",
            "required": true,
            "default": "gen_random_uuid()",
            "key": "Primary key",
            "meaning": "Primary identifier for one durable artifact pointer attached to a ledger event, such as a storage object, source path, report, screenshot, or generated file.",
            "constraints": "Required uuid column. Default: gen_random_uuid(). PRIMARY KEY: PRIMARY KEY (artifact_pointer_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_event_artifacts; referenced by model-grid evidence when that evidence has a linked artifact; nullable=false.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-artifact-pointer-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. UNIQUE: UNIQUE (event_id, artifact_key). UNIQUE: UNIQUE (event_id, artifact_key). UNIQUE: UNIQUE (event_id, artifact_key). UNIQUE: UNIQUE (event_id, artifact_key). FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_event_artifacts rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_event_artifacts rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-tenant-id"
          },
          {
            "name": "artifact_key",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Stable key for one artifact pointer within a ledger event; unique with event_id so evidence can be updated without ambiguity.",
            "constraints": "Required text column. UNIQUE: UNIQUE (event_id, artifact_key). UNIQUE: UNIQUE (event_id, artifact_key). UNIQUE: UNIQUE (event_id, artifact_key). UNIQUE: UNIQUE (event_id, artifact_key).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "repair-plan",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-artifact-key"
          },
          {
            "name": "artifact_kind",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Kind of artifact linked to the event, such as model output, screenshot, generated file, report, or source evidence.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "generated_file",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-artifact-kind"
          },
          {
            "name": "artifact_role",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Role the artifact played in the event, such as input, output, evidence, screenshot, repair, or promotion proof.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "evidence",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-artifact-role"
          },
          {
            "name": "storage_provider",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Storage system that holds the artifact when it is not represented only by a source URL/path.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "supabase-storage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-storage-provider"
          },
          {
            "name": "storage_bucket",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Storage bucket containing the artifact when storage_provider points at object storage.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop-artifacts",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-storage-bucket"
          },
          {
            "name": "storage_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Path evidence for incept_event_artifacts. It is diagnostic unless a canonical Platform3 artifact or Content/QTI row also references it.",
            "constraints": "Nullable text column. CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-storage-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-source-url"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-source-path"
          },
          {
            "name": "external_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Producer-supplied external artifact identifier when the evidence is known by a source system rather than by a Platform3 storage path.",
            "constraints": "Nullable text column. CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL). CHECK: CHECK (storage_path IS NOT NULL OR source_url IS NOT NULL OR source_path IS NOT NULL OR external_id IS NOT NULL).",
            "allowedValues": null,
            "relationship": "Free external identifier scoped by event_id and artifact_key; no Platform3 table is the target; nullable=true.",
            "example": "github-artifact-182763",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-external-id"
          },
          {
            "name": "media_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "MIME media type for the artifact payload, used by readers to render or validate evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "application/json",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-media-type"
          },
          {
            "name": "sha256",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "sha256 digest for artifact bytes, used to prove evidence identity without storing the artifact inline.",
            "constraints": "Nullable text column. CHECK: CHECK (sha256 IS NULL OR sha256 ~ '^sha256:[0-9a-f]{64}$'::text).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-sha256"
          },
          {
            "name": "byte_size",
            "type": "bigint(64)",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Artifact size in bytes, used for evidence validation and storage/debugging reports.",
            "constraints": "Nullable bigint(64) column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "4096",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-byte-size"
          },
          {
            "name": "metadata",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted operational metadata. Do not store secrets, raw PII, JWTs, IP addresses, or user agents.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(metadata) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-metadata"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-event-artifacts-created-at"
          }
        ],
        "anchor": "table-incept-incept-event-artifacts"
      },
      {
        "name": "incept.incept_quality_bars",
        "relationName": "incept_quality_bars",
        "title": "Quality Bars",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Versioned quality-bar definitions observed by Incept events. Changes are represented by ledger events; this table indexes the active definitions.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(quality_bar_id, quality_bar_version)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "CHECK: CHECK (jsonb_typeof(definition) = 'object'::text)",
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version)",
          "CHECK: CHECK (status = ANY (ARRAY['draft'::text, 'active'::text, 'superseded'::text, 'retired'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_quality_bars_event_idx ON incept.incept_quality_bars USING btree (event_id)",
          "CREATE UNIQUE INDEX incept_quality_bars_pkey ON incept.incept_quality_bars USING btree (quality_bar_id, quality_bar_version)",
          "CREATE INDEX incept_quality_bars_status_idx ON incept.incept_quality_bars USING btree (status, effective_at DESC)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_quality_bars where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version). PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version). PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version). PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version). PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version). PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version). PRIMARY KEY: PRIMARY KEY (quality_bar_id, quality_bar_version).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-quality-bar-version"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_quality_bars rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_quality_bars rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-tenant-id"
          },
          {
            "name": "name",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Human-readable name for the Incept definition row, such as the label of a quality bar.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "student-facing generated content quality bar",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-name"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": "'active'::text",
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. Default: 'active'::text. CHECK: CHECK (status = ANY (ARRAY['draft'::text, 'active'::text, 'superseded'::text, 'retired'::text])). Allowed values: draft means not yet active; active means usable for current evaluation; superseded means a newer row replaces this one; retired means no longer used for new work.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: draft means not yet active; active means usable for current evaluation; superseded means a newer row replaces this one; retired means no longer used for new work.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-status"
          },
          {
            "name": "effective_at",
            "type": "timestamptz",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Time a versioned quality bar becomes active for scoring or gating.",
            "constraints": "Required timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-effective-at"
          },
          {
            "name": "superseded_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Time a versioned quality bar is replaced by a newer definition.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-superseded-at"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-source-url"
          },
          {
            "name": "definition",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "JSON definition for the quality bar or governed policy object. It must be versioned and tied to ledger evidence.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(definition) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-definition"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-bars-created-at"
          }
        ],
        "anchor": "table-incept-incept-quality-bars"
      },
      {
        "name": "incept.incept_model_grid_evidence",
        "relationName": "incept_model_grid_evidence",
        "title": "Model Grid Evidence",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Typed index for model-grid evaluation evidence. The linked ledger event is canonical if this row and payload ever disagree.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(model_grid_evidence_id)",
        "relationships": [
          "artifact_pointer_id references incept.incept_event_artifacts.artifact_pointer_id.",
          "event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (artifact_pointer_id) REFERENCES incept.incept_event_artifacts(artifact_pointer_id)",
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "PRIMARY KEY: PRIMARY KEY (model_grid_evidence_id)",
          "CHECK: CHECK (jsonb_typeof(result) = 'object'::text)",
          "CHECK: CHECK (score IS NULL OR score >= 0::numeric)",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_model_grid_evidence_event_idx ON incept.incept_model_grid_evidence USING btree (event_id)",
          "CREATE INDEX incept_model_grid_evidence_grid_idx ON incept.incept_model_grid_evidence USING btree (grid_id, task_id, subtype_id, created_at DESC)",
          "CREATE UNIQUE INDEX incept_model_grid_evidence_pkey ON incept.incept_model_grid_evidence USING btree (model_grid_evidence_id)",
          "CREATE INDEX incept_model_grid_evidence_provider_idx ON incept.incept_model_grid_evidence USING btree (provider, model_name, created_at DESC)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_model_grid_evidence where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "model_grid_evidence_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Primary identifier for one model-grid evidence row at the run, grid, task, subtype, provider, and model comparison grain.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (model_grid_evidence_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_model_grid_evidence; projected by incept_model_grid_latest_v; nullable=false.",
            "example": "mg-ev-platform3-dd-001",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-model-grid-evidence-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_model_grid_evidence rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_model_grid_evidence rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-tenant-id"
          },
          {
            "name": "run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Soft reference to the model-grid execution run that produced this comparison evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to a model-grid run recorded in ledger payloads or external runner state; many evidence rows may share one run_id; nullable=true.",
            "example": "model-grid-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-run-id"
          },
          {
            "name": "grid_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Soft reference to the model-grid definition or comparison grid whose cells this evidence row populates.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to a model-grid definition recorded in ledger payloads or source files; many evidence rows may share one grid_id; nullable=true.",
            "example": "platform3-data-dictionary-grid",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-grid-id"
          },
          {
            "name": "task_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Soft reference to the individual evaluation task inside the model grid, such as generating a field description or reviewing a deliverable.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to a task definition inside the model-grid run; many provider/model rows may share one task_id; nullable=true.",
            "example": "describe-incept-reference-fields",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-task-id"
          },
          {
            "name": "subtype_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Soft reference to the content subtype or evaluation slice within the grid task, used to compare models on the same subtype grain.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to a subtype slice defined by the grid/task payload; many evidence rows may share one subtype_id; nullable=true.",
            "example": "reference-field-docs",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-subtype-id"
          },
          {
            "name": "provider",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "AI provider or execution provider that produced model-grid evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "openai",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-provider"
          },
          {
            "name": "model_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Model identifier used for a generation or evaluation run.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "gpt-5-codex",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-model-name"
          },
          {
            "name": "evaluator_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Identifier for the evaluator, grader, or judge configuration that produced model-grid evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "rubric-judge-platform-dd",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-evaluator-id"
          },
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-quality-bar-version"
          },
          {
            "name": "score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Numeric score produced by an evaluator or quality gate.",
            "constraints": "Nullable numeric column. CHECK: CHECK (score IS NULL OR score >= 0::numeric).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-score"
          },
          {
            "name": "passed",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Boolean result of a quality, model-grid, layer-health, or projection check.",
            "constraints": "Nullable boolean column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-passed"
          },
          {
            "name": "latency_ms",
            "type": "integer(32)",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Measured latency in milliseconds for a model-grid task or evaluation.",
            "constraints": "Nullable integer(32) column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-latency-ms"
          },
          {
            "name": "cost_usd",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Estimated task cost in US dollars for model-grid comparison.",
            "constraints": "Nullable numeric column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-cost-usd"
          },
          {
            "name": "artifact_pointer_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Optional link to the artifact pointer that stores the model output, judge trace, screenshot, or generated file behind this evidence row.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (artifact_pointer_id) REFERENCES incept.incept_event_artifacts(artifact_pointer_id).",
            "allowedValues": null,
            "relationship": "Many incept_model_grid_evidence rows reference one incept.incept_event_artifacts.artifact_pointer_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-artifact-pointer-id"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-source-url"
          },
          {
            "name": "result",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Typed evaluation result payload for model-grid or quality evidence.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(result) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-result"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-evidence-created-at"
          }
        ],
        "anchor": "table-incept-incept-model-grid-evidence"
      },
      {
        "name": "incept.incept_customer_feedback",
        "relationName": "incept_customer_feedback",
        "title": "Customer Feedback",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Typed index for customer and GitHub-linked quality evidence that has been normalized into ledger events.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(feedback_id)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (jsonb_typeof(normalized_payload) = 'object'::text AND jsonb_typeof(redacted_customer) = 'object'::text)",
          "PRIMARY KEY: PRIMARY KEY (feedback_id)",
          "CHECK: CHECK (status = ANY (ARRAY['open'::text, 'routed'::text, 'repairing'::text, 'resolved'::text, 'closed'::text, 'superseded'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE UNIQUE INDEX incept_customer_feedback_evidence_uidx ON incept.incept_customer_feedback USING btree (evidence_id) WHERE (evidence_id IS NOT NULL)",
          "CREATE INDEX incept_customer_feedback_loop_idx ON incept.incept_customer_feedback USING btree (loop_id, received_at DESC)",
          "CREATE UNIQUE INDEX incept_customer_feedback_pkey ON incept.incept_customer_feedback USING btree (feedback_id)",
          "CREATE INDEX incept_customer_feedback_status_idx ON incept.incept_customer_feedback USING btree (status, received_at DESC)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_customer_feedback where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "feedback_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Primary identifier for one normalized customer, operator, or GitHub feedback item linked into the Incept evidence stream.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (feedback_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_customer_feedback; projected by incept_customer_feedback_status_v; nullable=false.",
            "example": "feedback-GH-148",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-feedback-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_customer_feedback rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_customer_feedback rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-tenant-id"
          },
          {
            "name": "evidence_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Soft reference to the source evidence item that the feedback was normalized from, such as a customer audit note, issue comment, or generated report finding.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to source evidence recorded in ledger payloads or external systems; many feedback rows may share one evidence_id; nullable=true.",
            "example": "evidence-platform3-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-evidence-id"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": "'open'::text",
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. Default: 'open'::text. CHECK: CHECK (status = ANY (ARRAY['open'::text, 'routed'::text, 'repairing'::text, 'resolved'::text, 'closed'::text, 'superseded'::text])). Allowed values: open means unresolved customer or issue evidence; routed means assigned to a repair or owner path; repairing means active correction work is underway; resolved means the underlying issue has a accepted fix; closed means no further action is currently expected; superseded means a newer row replaces this one.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: open means unresolved customer or issue evidence; routed means assigned to a repair or owner path; repairing means active correction work is underway; resolved means the underlying issue has a accepted fix; closed means no further action is currently expected; superseded means a newer row replaces this one.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status"
          },
          {
            "name": "source_type",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Type of source evidence, such as GitHub issue, customer audit, operator note, or generated report.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "github_issue",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-source-type"
          },
          {
            "name": "severity",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Severity label assigned to customer feedback or issue evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "blocking",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-severity"
          },
          {
            "name": "expected_blocking",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Boolean indicating whether the feedback is expected to block promotion or release.",
            "constraints": "Nullable boolean column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-expected-blocking"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-skill-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-loop-id"
          },
          {
            "name": "artifact_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Generated or evaluated artifact identifier from the producer workflow.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "artifact-platform-dd-index-html",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-artifact-id"
          },
          {
            "name": "github_issue_key",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Stable GitHub issue key used to connect feedback/status views to the external issue tracker.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "GH-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-github-issue-key"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-source-url"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-source-path"
          },
          {
            "name": "received_at",
            "type": "timestamptz",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Time the customer feedback or issue evidence was received by the governed Incept pipeline.",
            "constraints": "Required timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-received-at"
          },
          {
            "name": "normalized_payload",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted normalized JSON payload for feedback or customer evidence after source-specific parsing.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(normalized_payload) = 'object'::text AND jsonb_typeof(redacted_customer) = 'object'::text). CHECK: CHECK (jsonb_typeof(normalized_payload) = 'object'::text AND jsonb_typeof(redacted_customer) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-normalized-payload"
          },
          {
            "name": "redacted_customer",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted customer identity/context object. It must not contain direct PII or credentials.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(normalized_payload) = 'object'::text AND jsonb_typeof(redacted_customer) = 'object'::text). CHECK: CHECK (jsonb_typeof(normalized_payload) = 'object'::text AND jsonb_typeof(redacted_customer) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-redacted-customer"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-created-at"
          }
        ],
        "anchor": "table-incept-incept-customer-feedback"
      },
      {
        "name": "incept.incept_repair_attempts",
        "relationName": "incept_repair_attempts",
        "title": "Repair Attempts",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Typed index for repair attempts created by loop events. Promotion acceptance remains a separate decision row linked to the attempt.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(repair_attempt_id)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "loop_run_id references incept.incept_loop_runs.loop_run_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text)",
          "FOREIGN KEY: FOREIGN KEY (loop_run_id) REFERENCES incept.incept_loop_runs(loop_run_id)",
          "PRIMARY KEY: PRIMARY KEY (repair_attempt_id)",
          "CHECK: CHECK (status = ANY (ARRAY['running'::text, 'succeeded'::text, 'failed'::text, 'rejected'::text, 'promoted'::text, 'superseded'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_repair_attempts_event_idx ON incept.incept_repair_attempts USING btree (event_id)",
          "CREATE INDEX incept_repair_attempts_loop_idx ON incept.incept_repair_attempts USING btree (loop_id, started_at DESC)",
          "CREATE UNIQUE INDEX incept_repair_attempts_loop_run_attempt_uidx ON incept.incept_repair_attempts USING btree (loop_run_id, loop_id, attempt_index) WHERE ((loop_run_id IS NOT NULL) AND (loop_id IS NOT NULL) AND (attempt_index IS NOT NULL))",
          "CREATE UNIQUE INDEX incept_repair_attempts_pkey ON incept.incept_repair_attempts USING btree (repair_attempt_id)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_repair_attempts where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "repair_attempt_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Primary identifier for one repair attempt spawned from feedback, quality evidence, or loop failure.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (repair_attempt_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_repair_attempts; referenced by promotion decisions and progress projections; nullable=false.",
            "example": "repair-platform3-148-a3",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-repair-attempt-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_repair_attempts rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_repair_attempts rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-tenant-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. FOREIGN KEY: FOREIGN KEY (loop_run_id) REFERENCES incept.incept_loop_runs(loop_run_id).",
            "allowedValues": null,
            "relationship": "Many incept_repair_attempts rows reference one incept.incept_loop_runs.loop_run_id; nullable=true.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-loop-run-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-skill-id"
          },
          {
            "name": "attempt_index",
            "type": "integer(32)",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Ordinal repair-attempt number within a run, loop, or skill repair sequence.",
            "constraints": "Nullable integer(32) column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-attempt-index"
          },
          {
            "name": "generator",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Generator, model, or agent process that produced a repair candidate.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "codex-exec",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-generator"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": "'running'::text",
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. Default: 'running'::text. CHECK: CHECK (status = ANY (ARRAY['running'::text, 'succeeded'::text, 'failed'::text, 'rejected'::text, 'promoted'::text, 'superseded'::text])). Allowed values: running means actively executing; succeeded means completed successfully; failed means completed with an error; rejected means the candidate did not meet the bar; promoted means accepted into the next version path; superseded means a newer row replaces this one.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: running means actively executing; succeeded means completed successfully; failed means completed with an error; rejected means the candidate did not meet the bar; promoted means accepted into the next version path; superseded means a newer row replaces this one.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-status"
          },
          {
            "name": "candidate_version_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Version identifier for the repaired candidate artifact, prompt, skill, or generated content proposed by this attempt.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to an Incept candidate version recorded in the attempt result_payload, artifact pointers, or canonical Content/QTI materialization; many repair attempts may reference one candidate version; nullable=true.",
            "example": "candidate-version-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-candidate-version-id"
          },
          {
            "name": "candidate_eval_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Evaluation-run identifier for the judge, verifier, or model-grid run that assessed this repair candidate.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to an evaluation run recorded in ledger payloads or model-grid evidence; many repair attempts may reference one candidate evaluation run; nullable=true.",
            "example": "eval-run-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-candidate-eval-run-id"
          },
          {
            "name": "candidate_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Path evidence for incept_repair_attempts. It is diagnostic unless a canonical Platform3 artifact or Content/QTI row also references it.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-candidate-path"
          },
          {
            "name": "started_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Time the run or repair attempt started.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-started-at"
          },
          {
            "name": "completed_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Time the run or repair attempt reached a terminal state.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-completed-at"
          },
          {
            "name": "baseline_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Score value used by incept_repair_attempts; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-baseline-score"
          },
          {
            "name": "candidate_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Score value used by incept_repair_attempts; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-candidate-score"
          },
          {
            "name": "ai_oversight",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "JSON evidence of AI oversight, reviewer reasoning, or automated promotion review.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-ai-oversight"
          },
          {
            "name": "feedback_summary",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted structured summary of feedback that drove a repair attempt.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-feedback-summary"
          },
          {
            "name": "result_payload",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Typed result payload for repair, promotion, or deployment evidence.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(feedback_summary) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-result-payload"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-source-url"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-repair-attempts-created-at"
          }
        ],
        "anchor": "table-incept-incept-repair-attempts"
      },
      {
        "name": "incept.incept_promotion_decisions",
        "relationName": "incept_promotion_decisions",
        "title": "Promotion Decisions",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "AI-oversight repair and promotion decisions. This records the decision index; the event ledger preserves the canonical payload.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(promotion_decision_id)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "loop_run_id references incept.incept_loop_runs.loop_run_id.",
          "repair_attempt_id references incept.incept_repair_attempts.repair_attempt_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text)",
          "FOREIGN KEY: FOREIGN KEY (loop_run_id) REFERENCES incept.incept_loop_runs(loop_run_id)",
          "PRIMARY KEY: PRIMARY KEY (promotion_decision_id)",
          "FOREIGN KEY: FOREIGN KEY (repair_attempt_id) REFERENCES incept.incept_repair_attempts(repair_attempt_id)",
          "CHECK: CHECK (decision_status = ANY (ARRAY['accepted'::text, 'rejected'::text, 'deferred'::text, 'landed'::text, 'landing_failed'::text, 'superseded'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_promotion_decisions_candidate_idx ON incept.incept_promotion_decisions USING btree (candidate_version_id)",
          "CREATE INDEX incept_promotion_decisions_event_idx ON incept.incept_promotion_decisions USING btree (event_id)",
          "CREATE INDEX incept_promotion_decisions_loop_idx ON incept.incept_promotion_decisions USING btree (loop_id, decided_at DESC)",
          "CREATE UNIQUE INDEX incept_promotion_decisions_pkey ON incept.incept_promotion_decisions USING btree (promotion_decision_id)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_promotion_decisions where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "promotion_decision_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Primary identifier for one AI-oversight promotion decision comparing a candidate version with the prior baseline.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (promotion_decision_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_promotion_decisions; projected by incept_promotion_timeline_v; nullable=false.",
            "example": "promotion-platform3-148-a3",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-promotion-decision-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_promotion_decisions rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_promotion_decisions rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-tenant-id"
          },
          {
            "name": "repair_attempt_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Repair attempt whose candidate was evaluated for promotion by this decision row.",
            "constraints": "Nullable text column. FOREIGN KEY: FOREIGN KEY (repair_attempt_id) REFERENCES incept.incept_repair_attempts(repair_attempt_id).",
            "allowedValues": null,
            "relationship": "Many incept_promotion_decisions rows reference one incept.incept_repair_attempts.repair_attempt_id; nullable=true.",
            "example": "repair-platform3-148-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-repair-attempt-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. FOREIGN KEY: FOREIGN KEY (loop_run_id) REFERENCES incept.incept_loop_runs(loop_run_id).",
            "allowedValues": null,
            "relationship": "Many incept_promotion_decisions rows reference one incept.incept_loop_runs.loop_run_id; nullable=true.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-loop-run-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-skill-id"
          },
          {
            "name": "baseline_version_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Version identifier for the prior accepted artifact, skill, or generated content used as the promotion baseline.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to an Incept baseline version recorded in promotion evidence, artifact pointers, or canonical Content/QTI materialization; many promotion decisions may compare against one baseline version; nullable=true.",
            "example": "baseline-version-platform-dd-a2",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-baseline-version-id"
          },
          {
            "name": "candidate_version_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Version identifier for the candidate artifact, skill, or generated content being considered for promotion.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to an Incept candidate version recorded in promotion evidence, artifact pointers, or canonical Content/QTI materialization; many promotion decisions may evaluate one candidate version; nullable=true.",
            "example": "candidate-version-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-candidate-version-id"
          },
          {
            "name": "candidate_eval_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Evaluation-run identifier whose results support accepting, rejecting, deferring, or landing the candidate.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to an evaluation run recorded in ledger payloads or model-grid evidence; many promotion decisions may use one candidate evaluation run; nullable=true.",
            "example": "eval-run-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-candidate-eval-run-id"
          },
          {
            "name": "previous_best_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Score value used by incept_promotion_decisions; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-previous-best-score"
          },
          {
            "name": "candidate_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Score value used by incept_promotion_decisions; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-candidate-score"
          },
          {
            "name": "accepted",
            "type": "boolean",
            "required": true,
            "default": "false",
            "key": "Field",
            "meaning": "Boolean promotion decision result: true means the candidate was accepted by policy or oversight.",
            "constraints": "Required boolean column. Default: false. CHECK: CHECK (decision_status = ANY (ARRAY['accepted'::text, 'rejected'::text, 'deferred'::text, 'landed'::text, 'landing_failed'::text, 'superseded'::text])). Allowed values: accepted means selected by promotion policy; rejected means the candidate did not meet the bar; deferred means intentionally postponed with reason; landed means merged or deployed; landing_failed means merge/deploy failed after acceptance; superseded means a newer row replaces this one.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "true",
            "invalidWhen": "null; outside allowed values: accepted means selected by promotion policy; rejected means the candidate did not meet the bar; deferred means intentionally postponed with reason; landed means merged or deployed; landing_failed means merge/deploy failed after acceptance; superseded means a newer row replaces this one.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-accepted"
          },
          {
            "name": "decision_status",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Status value projected by incept_promotion_decisions; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Required text column. CHECK: CHECK (decision_status = ANY (ARRAY['accepted'::text, 'rejected'::text, 'deferred'::text, 'landed'::text, 'landing_failed'::text, 'superseded'::text])). Allowed values: accepted means selected by promotion policy; rejected means the candidate did not meet the bar; deferred means intentionally postponed with reason; landed means merged or deployed; landing_failed means merge/deploy failed after acceptance; superseded means a newer row replaces this one.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: accepted means selected by promotion policy; rejected means the candidate did not meet the bar; deferred means intentionally postponed with reason; landed means merged or deployed; landing_failed means merge/deploy failed after acceptance; superseded means a newer row replaces this one.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-decision-status"
          },
          {
            "name": "decided_at",
            "type": "timestamptz",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Time a promotion or repair decision was made.",
            "constraints": "Required timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-decided-at"
          },
          {
            "name": "actor_subject",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Pseudonymous subject for the actor; do not store credentials, JWTs, or direct customer PII here.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "agent:codex:data-dictionary-doer",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-actor-subject"
          },
          {
            "name": "ai_oversight",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "JSON evidence of AI oversight, reviewer reasoning, or automated promotion review.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-ai-oversight"
          },
          {
            "name": "decision_reason",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Redacted reason for a promotion decision, suitable for audit and customer-facing status reports.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "candidate met the published quality bar and materialized Content/QTI rows",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-decision-reason"
          },
          {
            "name": "deployment_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Deployment or landing attempt associated with an accepted promotion decision.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Soft reference to incept.incept_deployments.deployment_id; many promotion decisions may point at one deployment when a landing batch covers several decisions; nullable=true.",
            "example": "deploy-platform3-preview-20260625",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-deployment-id"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-source-url"
          },
          {
            "name": "result_payload",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Typed result payload for repair, promotion, or deployment evidence.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). CHECK: CHECK (jsonb_typeof(ai_oversight) = 'object'::text AND jsonb_typeof(result_payload) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-result-payload"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-decisions-created-at"
          }
        ],
        "anchor": "table-incept-incept-promotion-decisions"
      },
      {
        "name": "incept.incept_external_issue_links",
        "relationName": "incept_external_issue_links",
        "title": "External Issue Links",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Links from ledger events to GitHub Issues and other external trackers. GitHub remains the issue tracker; this table only links issues into Incept evidence.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(external_issue_link_id)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "UNIQUE: UNIQUE (external_issue_key)",
          "CHECK: CHECK (jsonb_typeof(metadata) = 'object'::text)",
          "PRIMARY KEY: PRIMARY KEY (external_issue_link_id)",
          "CHECK: CHECK (status = ANY (ARRAY['open'::text, 'routed'::text, 'linked'::text, 'closed'::text, 'ignored'::text, 'superseded'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_external_issue_links_event_idx ON incept.incept_external_issue_links USING btree (event_id)",
          "CREATE UNIQUE INDEX incept_external_issue_links_external_issue_key_key ON incept.incept_external_issue_links USING btree (external_issue_key)",
          "CREATE UNIQUE INDEX incept_external_issue_links_key_uidx ON incept.incept_external_issue_links USING btree (external_issue_key)",
          "CREATE UNIQUE INDEX incept_external_issue_links_pkey ON incept.incept_external_issue_links USING btree (external_issue_link_id)",
          "CREATE INDEX incept_external_issue_links_repo_idx ON incept.incept_external_issue_links USING btree (external_system, repo, issue_number)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_external_issue_links where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "external_issue_link_id",
            "type": "uuid",
            "required": true,
            "default": "gen_random_uuid()",
            "key": "Primary key",
            "meaning": "Primary identifier for one governed link between an Incept ledger event and an external issue tracker item.",
            "constraints": "Required uuid column. Default: gen_random_uuid(). PRIMARY KEY: PRIMARY KEY (external_issue_link_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_external_issue_links; nullable=false.",
            "example": "7be8fc8c-f6f4-4651-97f1-b6b911f6640b",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-external-issue-link-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_external_issue_links rows reference one incept.incept_event_ledger.event_id; nullable=true.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_external_issue_links rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-tenant-id"
          },
          {
            "name": "external_issue_key",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Stable external issue key that connects Platform3 evidence to GitHub or another tracker.",
            "constraints": "Required text column. UNIQUE: UNIQUE (external_issue_key).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "GH-148",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-external-issue-key"
          },
          {
            "name": "external_system",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "External tracker or system linked to the Incept evidence, such as GitHub.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "github",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-external-system"
          },
          {
            "name": "repo",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository owner/name associated with an external issue or source evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "andymontgomery-byte/platform3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-repo"
          },
          {
            "name": "issue_number",
            "type": "integer(32)",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Numeric issue identifier in the external tracker.",
            "constraints": "Nullable integer(32) column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-issue-number"
          },
          {
            "name": "external_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Source-system issue identifier when it differs from the normalized external_issue_key.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "Free external identifier scoped by external_system and repo; no Platform3 table is the target; nullable=true.",
            "example": "github-artifact-182763",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-external-id"
          },
          {
            "name": "url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External issue or evidence URL. It must not include credentials or secret query parameters.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-url"
          },
          {
            "name": "source_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Type of source evidence, such as GitHub issue, customer audit, operator note, or generated report.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "github_issue",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-source-type"
          },
          {
            "name": "issue_kind",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Classification of the external issue, such as bug, feature, documentation, or quality feedback.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "bug",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-issue-kind"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": "'open'::text",
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. Default: 'open'::text. CHECK: CHECK (status = ANY (ARRAY['open'::text, 'routed'::text, 'linked'::text, 'closed'::text, 'ignored'::text, 'superseded'::text])). Allowed values: open means unresolved customer or issue evidence; routed means assigned to a repair or owner path; linked means an external issue has been connected to evidence; closed means no further action is currently expected; ignored means intentionally excluded with reason in metadata; superseded means a newer row replaces this one.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: open means unresolved customer or issue evidence; routed means assigned to a repair or owner path; linked means an external issue has been connected to evidence; closed means no further action is currently expected; ignored means intentionally excluded with reason in metadata; superseded means a newer row replaces this one.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-status"
          },
          {
            "name": "linked_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Time external issue evidence was linked into the Incept evidence graph.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-linked-at"
          },
          {
            "name": "opened_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External issue open time copied from the source tracker.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-opened-at"
          },
          {
            "name": "closed_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External issue close time copied from the source tracker.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-closed-at"
          },
          {
            "name": "metadata",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted operational metadata. Do not store secrets, raw PII, JWTs, IP addresses, or user agents.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(metadata) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-external-issue-links-metadata"
          }
        ],
        "anchor": "table-incept-incept-external-issue-links"
      },
      {
        "name": "incept.incept_deployments",
        "relationName": "incept_deployments",
        "title": "Deployments",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Deployment and landing attempts linked to promotion, repair, and release events.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(deployment_id)",
        "relationships": [
          "event_id references incept.incept_event_ledger.event_id.",
          "tenant_id references platform.tenant.tenant_id."
        ],
        "constraints": [
          "FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "CHECK: CHECK (jsonb_typeof(metadata) = 'object'::text)",
          "PRIMARY KEY: PRIMARY KEY (deployment_id)",
          "CHECK: CHECK (status = ANY (ARRAY['queued'::text, 'running'::text, 'succeeded'::text, 'failed'::text, 'cancelled'::text, 'rolled_back'::text]))",
          "FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id)"
        ],
        "indexes": [
          "CREATE INDEX incept_deployments_commit_idx ON incept.incept_deployments USING btree (commit_sha, deployed_at DESC)",
          "CREATE INDEX incept_deployments_event_idx ON incept.incept_deployments USING btree (event_id)",
          "CREATE UNIQUE INDEX incept_deployments_pkey ON incept.incept_deployments USING btree (deployment_id)"
        ],
        "projectionRules": [
          "Typed index table for a specific Incept evidence class. The linked incept_event_ledger row is canonical if this typed index and the event payload disagree.",
          "Rows are tenant-scoped Platform3 producer facts and must be read through a governed API/view path with normal auth and audit."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_deployments where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "deployment_id",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Primary identifier for one deployment, landing, rollback, or release attempt linked to promotion and repair evidence.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (deployment_id).",
            "allowedValues": null,
            "relationship": "Primary key for incept.incept_deployments; soft-referenced by promotion decisions and promotion timeline projections; nullable=false.",
            "example": "deploy-platform3-preview-20260625",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-deployment-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": true,
            "default": null,
            "key": "Foreign key",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Required uuid column. FOREIGN KEY: FOREIGN KEY (event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_deployments rows reference one incept.incept_event_ledger.event_id; nullable=false.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "null; does not resolve to the canonical ledger event when a foreign key is required",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (tenant_id) REFERENCES platform.tenant(tenant_id).",
            "allowedValues": null,
            "relationship": "Many incept_deployments rows reference one platform.tenant.tenant_id; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-tenant-id"
          },
          {
            "name": "environment",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Deployment environment for a deployment row, such as preview, staging, production, or rollback target.",
            "constraints": "Required text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "preview",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-environment"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. CHECK: CHECK (status = ANY (ARRAY['queued'::text, 'running'::text, 'succeeded'::text, 'failed'::text, 'cancelled'::text, 'rolled_back'::text])). Allowed values: queued means accepted but not started; running means actively executing; succeeded means completed successfully; failed means completed with an error; cancelled means intentionally stopped before completion; rolled_back means a deployment or promotion was reverted.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: queued means accepted but not started; running means actively executing; succeeded means completed successfully; failed means completed with an error; cancelled means intentionally stopped before completion; rolled_back means a deployment or promotion was reverted.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-status"
          },
          {
            "name": "deployed_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Time deployment evidence says the candidate was deployed or rolled back.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-deployed-at"
          },
          {
            "name": "repo_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository URL associated with the event or deployment evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-repo-url"
          },
          {
            "name": "branch_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Git branch associated with the event or deployment evidence.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "platform3-148-incept-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-branch-name"
          },
          {
            "name": "commit_sha",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Git commit SHA tied to the event, repair, promotion, or deployment.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-commit-sha"
          },
          {
            "name": "pull_request_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Pull request URL linked to a repair, promotion, or deployment event.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-pull-request-url"
          },
          {
            "name": "deployment_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "URL evidence for incept_deployments. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-deployment-url"
          },
          {
            "name": "actor_subject",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Pseudonymous subject for the actor; do not store credentials, JWTs, or direct customer PII here.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "agent:codex:data-dictionary-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-actor-subject"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-source-url"
          },
          {
            "name": "metadata",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted operational metadata. Do not store secrets, raw PII, JWTs, IP addresses, or user agents.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(metadata) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-metadata"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-deployments-created-at"
          }
        ],
        "anchor": "table-incept-incept-deployments"
      },
      {
        "name": "incept.incept_projection_checkpoints",
        "relationName": "incept_projection_checkpoints",
        "title": "Projection Checkpoints",
        "kind": "table",
        "sourceClass": "Incept governed table",
        "purpose": "Materialization checkpoints for ledger-backed projections. The first supported projection is data/generation-loop-progress-report.json.",
        "lifecycle": "Tenant-scoped producer fact or typed index row. Ledger facts are append-only; typed index rows preserve queryable evidence while the event ledger remains canonical on disagreement.",
        "primaryKey": "(projection_name, projection_version, checkpoint_key)",
        "relationships": [
          "last_event_id references incept.incept_event_ledger.event_id."
        ],
        "constraints": [
          "CHECK: CHECK (jsonb_typeof(summary) = 'object'::text AND jsonb_typeof(watermark) = 'object'::text)",
          "FOREIGN KEY: FOREIGN KEY (last_event_id) REFERENCES incept.incept_event_ledger(event_id)",
          "PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key)",
          "CHECK: CHECK (status = ANY (ARRAY['current'::text, 'stale'::text, 'failed'::text, 'backfilling'::text]))"
        ],
        "indexes": [
          "CREATE INDEX incept_projection_checkpoints_materialized_idx ON incept.incept_projection_checkpoints USING btree (materialized_at DESC)",
          "CREATE UNIQUE INDEX incept_projection_checkpoints_pkey ON incept.incept_projection_checkpoints USING btree (projection_name, projection_version, checkpoint_key)"
        ],
        "projectionRules": [
          "Checkpoint rows record materialized projection progress. They do not replace the ledger; they prove which event watermark produced a report or view input.",
          "Progress projections must be reproducible from ledger rows plus checkpoint rows."
        ],
        "viewDefinition": null,
        "exampleQuery": "select * from incept.incept_projection_checkpoints where tenant_id = $1 order by created_at desc limit 50;",
        "fields": [
          {
            "name": "projection_name",
            "type": "text",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Name of the materialized projection tracked by a checkpoint.",
            "constraints": "Required text column. PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "generation-loop-progress-report",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-projection-name"
          },
          {
            "name": "projection_version",
            "type": "integer(32)",
            "required": true,
            "default": null,
            "key": "Primary key",
            "meaning": "Version of the projection contract used to materialize checkpointed output.",
            "constraints": "Required integer(32) column. PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key).",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "3",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-projection-version"
          },
          {
            "name": "checkpoint_key",
            "type": "text",
            "required": true,
            "default": "'default'::text",
            "key": "Primary key",
            "meaning": "Key identifying the checkpoint instance within a projection/version.",
            "constraints": "Required text column. Default: 'default'::text. PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key). PRIMARY KEY: PRIMARY KEY (projection_name, projection_version, checkpoint_key).",
            "allowedValues": null,
            "relationship": "Free or soft identifier with no enforced foreign key in this catalog snapshot; scope and target are stated by the field meaning and object purpose.",
            "example": "generation-loop-progress-report:2026-06-25",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-checkpoint-key"
          },
          {
            "name": "last_event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Foreign key",
            "meaning": "Last canonical ledger event included in this projection checkpoint watermark.",
            "constraints": "Nullable uuid column. FOREIGN KEY: FOREIGN KEY (last_event_id) REFERENCES incept.incept_event_ledger(event_id).",
            "allowedValues": null,
            "relationship": "Many incept_projection_checkpoints rows may reference one incept.incept_event_ledger.event_id as their last included event; nullable=true.",
            "example": "0df95d01-829f-4d0e-8ed7-a8916dd2c9d4",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-last-event-id"
          },
          {
            "name": "last_event_recorded_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Recorded timestamp of the last ledger event included in a projection checkpoint.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-last-event-recorded-at"
          },
          {
            "name": "last_event_occurred_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Occurred timestamp of the last ledger event included in a projection checkpoint.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-last-event-occurred-at"
          },
          {
            "name": "source_event_count",
            "type": "bigint(64)",
            "required": true,
            "default": "0",
            "key": "Field",
            "meaning": "Number of source ledger events included in a projection checkpoint.",
            "constraints": "Required bigint(64) column. Default: 0.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "1",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-source-event-count"
          },
          {
            "name": "materialized_at",
            "type": "timestamptz",
            "required": true,
            "default": "now()",
            "key": "Field",
            "meaning": "Time a projection checkpoint was materialized.",
            "constraints": "Required timestamptz column. Default: now(). Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "null",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-materialized-at"
          },
          {
            "name": "output_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Field",
            "meaning": "Path evidence for incept_projection_checkpoints. It is diagnostic unless a canonical Platform3 artifact or Content/QTI row also references it.",
            "constraints": "Nullable text column.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-output-path"
          },
          {
            "name": "status",
            "type": "text",
            "required": true,
            "default": "'current'::text",
            "key": "Field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Required text column. Default: 'current'::text. CHECK: CHECK (status = ANY (ARRAY['current'::text, 'stale'::text, 'failed'::text, 'backfilling'::text])). Allowed values: current means projection is up to date at its watermark; stale means projection lags the ledger; failed means completed with an error; backfilling means projection is rebuilding historical rows.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "running",
            "invalidWhen": "null; outside allowed values: current means projection is up to date at its watermark; stale means projection lags the ledger; failed means completed with an error; backfilling means projection is rebuilding historical rows.",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-status"
          },
          {
            "name": "summary",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Redacted summary object used for reports and checkpoint evidence.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(summary) = 'object'::text AND jsonb_typeof(watermark) = 'object'::text). CHECK: CHECK (jsonb_typeof(summary) = 'object'::text AND jsonb_typeof(watermark) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-summary"
          },
          {
            "name": "watermark",
            "type": "jsonb",
            "required": true,
            "default": "'{}'::jsonb",
            "key": "Field",
            "meaning": "Projection watermark describing which ledger facts were included.",
            "constraints": "Required jsonb column. Default: '{}'::jsonb. CHECK: CHECK (jsonb_typeof(summary) = 'object'::text AND jsonb_typeof(watermark) = 'object'::text). CHECK: CHECK (jsonb_typeof(summary) = 'object'::text AND jsonb_typeof(watermark) = 'object'::text). Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "allowedValues": null,
            "relationship": "No object relationship; this field is scalar evidence interpreted at the object grain.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "null; contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-projection-checkpoints-watermark"
          }
        ],
        "anchor": "table-incept-incept-projection-checkpoints"
      },
      {
        "name": "incept.incept_regeneration_event_timeline_v",
        "relationName": "incept_regeneration_event_timeline_v",
        "title": "Regeneration Event Timeline view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Flat event timeline for regeneration, evaluation, repair, promotion, deployment, and supervisor report reconstruction.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the projection rule. Raw-DB readers must apply the same tenant/auth/audit guardrails as the API path before returning rows.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT e.event_id,\n    e.tenant_id,\n    e.event_type,\n    e.event_schema_version,\n    e.idempotency_key,\n    e.operation_id,\n    e.request_id,\n    e.trace_id,\n    e.correlation_id,\n    e.loop_run_id,\n    lr.event_config_id,\n    lr.trigger_name,\n    COALESCE(e.loop_id, NULLIF(array_to_string(lr.loop_ids, ','::text), ''::text)) AS loop_scope,\n    e.loop_id,\n    e.skill_id,\n    e.content_type,\n    e.content_subtype,\n    e.quality_bar_id,\n    e.quality_bar_version,\n    e.actor_type,\n    e.actor_subject,\n    e.actor_agent_id,\n    e.actor_agent_model,\n    e.repo_url,\n    e.branch_name,\n    e.base_branch,\n    e.commit_sha,\n    e.worktree_path,\n    e.source_system,\n    e.source_url,\n    e.source_path,\n    e.occurred_at,\n    e.recorded_at,\n    e.payload,\n    e.redacted_metadata\n   FROM incept.incept_event_ledger e\n     LEFT JOIN incept.incept_loop_runs lr ON lr.loop_run_id = e.loop_run_id;",
        "exampleQuery": "select * from incept.incept_regeneration_event_timeline_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-tenant-id"
          },
          {
            "name": "event_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Governed event label that names what happened in the generation loop.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "incept.producer_surface.registered",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-event-type"
          },
          {
            "name": "event_schema_version",
            "type": "integer(32)",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Version of the payload contract used by this event.",
            "constraints": "Nullable integer(32) column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-event-schema-version"
          },
          {
            "name": "idempotency_key",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Deterministic writer key that prevents duplicate canonical events for the same producer operation.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "incept-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-idempotency-key"
          },
          {
            "name": "operation_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Stable operation name used for audit, idempotency, and support correlation.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "incept.producer_surface.register",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-operation-id"
          },
          {
            "name": "request_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Request-instance identifier returned to callers and used in support/debug correlation.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "req_20260625_148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-request-id"
          },
          {
            "name": "trace_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "End-to-end trace identifier shared with logs, Problems, and audit rows.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "trace_20260625_148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-trace-id"
          },
          {
            "name": "correlation_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Cross-event correlation key for related generation, repair, promotion, and deployment facts.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "corr-platform3-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-correlation-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-loop-run-id"
          },
          {
            "name": "event_config_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected run-configuration id from incept_loop_runs, used to group timeline rows by the schedule, prompt set, or operator profile that launched them.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_loop_runs.event_config_id; soft reference to an Incept runner configuration outside this catalog snapshot; nullable=true.",
            "example": "event-config-platform3-nightly",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-event-config-id"
          },
          {
            "name": "trigger_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Named trigger that started the loop run, such as daemon schedule, manual operator run, issue triage, or backfill.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "manual_repair",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-trigger-name"
          },
          {
            "name": "loop_scope",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected run scope used by timeline views to distinguish single-loop events from global, daemon, or backfill events.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-loop-scope"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-skill-id"
          },
          {
            "name": "content_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Generated artifact type, such as lesson, question, script, or report component.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-content-type"
          },
          {
            "name": "content_subtype",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "More specific generated artifact subtype used for quality grids and model comparisons.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "mastery_gate_question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-content-subtype"
          },
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-quality-bar-version"
          },
          {
            "name": "actor_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Kind of actor that emitted or approved the fact, such as agent, human, system, or daemon.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "agent",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-actor-type"
          },
          {
            "name": "actor_subject",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Pseudonymous subject for the actor; do not store credentials, JWTs, or direct customer PII here.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "agent:codex:data-dictionary-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-actor-subject"
          },
          {
            "name": "actor_agent_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Agent identifier when the actor is an AI or automated process.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "agent-codex-data-dictionary-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-actor-agent-id"
          },
          {
            "name": "actor_agent_model",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Model name or version for the AI agent that produced or judged the event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "gpt-5-codex-2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-actor-agent-model"
          },
          {
            "name": "repo_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository URL associated with the event or deployment evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-repo-url"
          },
          {
            "name": "branch_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Git branch associated with the event or deployment evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-148-incept-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-branch-name"
          },
          {
            "name": "base_branch",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Base branch used for comparison, PR, or landing evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "main",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-base-branch"
          },
          {
            "name": "commit_sha",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Git commit SHA tied to the event, repair, promotion, or deployment.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-commit-sha"
          },
          {
            "name": "worktree_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Local or agent worktree path recorded as evidence; it is diagnostic and not a durable product URL.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-worktree-path"
          },
          {
            "name": "source_system",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "System that produced the evidence, such as GitHub, Workflowy, agent runner, deployment provider, or local backfill.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "github",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-source-system"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-source-url"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-source-path"
          },
          {
            "name": "occurred_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time the underlying event happened.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-occurred-at"
          },
          {
            "name": "recorded_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time Platform3 recorded the event.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-recorded-at"
          },
          {
            "name": "payload",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Typed event payload. The event schema version defines required keys; direct credentials, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-payload"
          },
          {
            "name": "redacted_metadata",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Small redacted operational metadata such as counts, hashes, timings, source paths, or summary labels.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-regeneration-event-timeline-v-redacted-metadata"
          }
        ],
        "anchor": "table-incept-incept-regeneration-event-timeline-v"
      },
      {
        "name": "incept.incept_progress_projection_input_v",
        "relationName": "incept_progress_projection_input_v",
        "title": "Progress Projection Input view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Normalized input for rebuilding the generation-loop progress projection from ledger facts.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the base projection rule. The Platform API joins it to incept.incept_event_ledger for tenant scope, contract/projection filters, and the redacted payload details needed by customer progress consumers.",
          "The Platform API exposes trafficClass from the ledger payload using incept_traffic_class values: customer, goal-run, or self-test. Missing legacy payload values default to customer; new owner-directed materialization runs must write goal-run, and loop self-tests must write self-test.",
          "For contractId=incept-customer-progress-v1 and projectionName=generation-loop-progress-report, the Platform API must expose enough event and payload details to compute current rows, titles, blocking reasons, capability numerator/denominator, accuracy numerator/denominator, held-out numerator/denominator, and score fields without direct SUPABASE_DB_URL access.",
          "For contractId=incept-customer-generation-ledger-v1, the same Platform API must expose redacted scope and repair evidence: subject, grade level, content type/subtype, dimension vector, status, failure reason, feedback/feedback summary, failed check ids, reviewer confidence, accuracy numerator/denominator, and score fields; inline API reads of this raw repair-evidence contract must be filtered and bounded before payload details are extracted.",
          "Headline Accuracy for customer progress pages counts only trafficClass=customer rows; goal-run and self-test rows remain available through the same API as drilldown lanes.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT e.event_id,\n    e.loop_run_id,\n    e.loop_id,\n    e.skill_id,\n    e.content_type,\n    e.content_subtype,\n    e.quality_bar_id,\n    e.quality_bar_version,\n    e.event_type,\n    e.occurred_at,\n    e.recorded_at,\n    e.payload ->> 'status'::text AS event_status,\n    e.payload ->> 'projectionStatus'::text AS projection_status,\n        CASE\n            WHEN (e.payload ->> 'currentScore'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (e.payload ->> 'currentScore'::text)::numeric\n            ELSE NULL::numeric\n        END AS current_score,\n        CASE\n            WHEN (e.payload ->> 'targetScore'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (e.payload ->> 'targetScore'::text)::numeric\n            ELSE NULL::numeric\n        END AS target_score,\n        CASE\n            WHEN lower(e.payload ->> 'customerAvailable'::text) = ANY (ARRAY['true'::text, 'false'::text]) THEN (e.payload ->> 'customerAvailable'::text)::boolean\n            ELSE NULL::boolean\n        END AS customer_available,\n        CASE\n            WHEN lower(e.payload ->> 'qualityCleared'::text) = ANY (ARRAY['true'::text, 'false'::text]) THEN (e.payload ->> 'qualityCleared'::text)::boolean\n            ELSE NULL::boolean\n        END AS quality_cleared,\n    pd.accepted AS promotion_accepted,\n    pd.candidate_version_id AS promoted_version_id,\n    pd.candidate_score AS promoted_score,\n    ra.repair_attempt_id,\n    ra.status AS repair_status\n   FROM incept.incept_event_ledger e\n     LEFT JOIN incept.incept_promotion_decisions pd ON pd.event_id = e.event_id\n     LEFT JOIN incept.incept_repair_attempts ra ON ra.event_id = e.event_id\n  WHERE e.event_type = ANY (ARRAY['loop.run.started'::text, 'loop.run.completed'::text, 'evaluation.completed'::text, 'quality_bar.evaluated'::text, 'quality_target.missed'::text, 'quality_target.cleared'::text, 'repair.attempt.started'::text, 'repair.attempt.completed'::text, 'promotion.decision.recorded'::text, 'deployment.completed'::text]);",
        "exampleQuery": "select * from incept.incept_progress_projection_input_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-event-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-loop-run-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-skill-id"
          },
          {
            "name": "content_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Generated artifact type, such as lesson, question, script, or report component.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-content-type"
          },
          {
            "name": "content_subtype",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "More specific generated artifact subtype used for quality grids and model comparisons.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "mastery_gate_question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-content-subtype"
          },
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-quality-bar-version"
          },
          {
            "name": "event_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Governed event label that names what happened in the generation loop.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "incept.producer_surface.registered",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-event-type"
          },
          {
            "name": "occurred_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time the underlying event happened.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-occurred-at"
          },
          {
            "name": "recorded_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time Platform3 recorded the event.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-recorded-at"
          },
          {
            "name": "event_status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Status value projected by incept_progress_projection_input_v; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-event-status"
          },
          {
            "name": "projection_status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Status value projected by incept_progress_projection_input_v; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-projection-status"
          },
          {
            "name": "current_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_progress_projection_input_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-current-score"
          },
          {
            "name": "target_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_progress_projection_input_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-target-score"
          },
          {
            "name": "customer_available",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean projection flag indicating whether generated output is available to the customer-facing path.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-customer-available"
          },
          {
            "name": "quality_cleared",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean projection flag indicating whether the quality bar cleared for the row or content slice.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-quality-cleared"
          },
          {
            "name": "promotion_accepted",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean projection flag indicating whether a promotion decision accepted the candidate.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-promotion-accepted"
          },
          {
            "name": "promoted_version_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected version id that was accepted or made customer-available for progress reporting.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only soft reference to the promoted candidate version from promotion/result payload evidence; nullable=true.",
            "example": "candidate-version-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-promoted-version-id"
          },
          {
            "name": "promoted_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_progress_projection_input_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-promoted-score"
          },
          {
            "name": "repair_attempt_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected repair attempt contributing the current progress status for the loop, skill, content type, or quality bar grain.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_repair_attempts.repair_attempt_id where repair evidence is present; many projection rows may reference one repair attempt; nullable=true.",
            "example": "repair-platform3-148-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-repair-attempt-id"
          },
          {
            "name": "repair_status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Status value projected by incept_progress_projection_input_v; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-progress-projection-input-v-repair-status"
          }
        ],
        "anchor": "table-incept-incept-progress-projection-input-v"
      },
      {
        "name": "incept.incept_quality_grid_fact_v",
        "relationName": "incept_quality_grid_fact_v",
        "title": "Quality Grid Fact view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Quality grid fact view by skill, content type, subtype, subject, grade, and quality bar.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the projection rule. Raw-DB readers must apply the same tenant/auth/audit guardrails as the API path before returning rows.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT event_id,\n    loop_run_id,\n    loop_id,\n    skill_id,\n    content_type,\n    content_subtype,\n    quality_bar_id,\n    quality_bar_version,\n    COALESCE(payload ->> 'subject'::text, payload #>> '{dimensionVector,subject}'::text[]) AS subject,\n    COALESCE(payload ->> 'gradeLevel'::text, payload #>> '{dimensionVector,gradeLevel}'::text[]) AS grade_level,\n    COALESCE(payload ->> 'inputRangeId'::text, payload #>> '{inputRange,id}'::text[]) AS input_range_id,\n        CASE\n            WHEN (payload ->> 'strictQualityScore'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (payload ->> 'strictQualityScore'::text)::numeric\n            ELSE NULL::numeric\n        END AS strict_quality_score,\n        CASE\n            WHEN (payload ->> 'progressScore'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (payload ->> 'progressScore'::text)::numeric\n            ELSE NULL::numeric\n        END AS progress_score,\n        CASE\n            WHEN (payload ->> 'targetScore'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (payload ->> 'targetScore'::text)::numeric\n            ELSE NULL::numeric\n        END AS target_score,\n        CASE\n            WHEN (payload ->> 'targetPassRate'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (payload ->> 'targetPassRate'::text)::numeric\n            ELSE NULL::numeric\n        END AS target_pass_rate,\n        CASE\n            WHEN (payload ->> 'passRate'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (payload ->> 'passRate'::text)::numeric\n            ELSE NULL::numeric\n        END AS pass_rate,\n        CASE\n            WHEN lower(payload ->> 'qualityCleared'::text) = ANY (ARRAY['true'::text, 'false'::text]) THEN (payload ->> 'qualityCleared'::text)::boolean\n            ELSE NULL::boolean\n        END AS quality_cleared,\n        CASE\n            WHEN lower(payload ->> 'customerAvailable'::text) = ANY (ARRAY['true'::text, 'false'::text]) THEN (payload ->> 'customerAvailable'::text)::boolean\n            ELSE NULL::boolean\n        END AS customer_available,\n        CASE\n            WHEN lower(payload ->> 'quarantined'::text) = ANY (ARRAY['true'::text, 'false'::text]) THEN (payload ->> 'quarantined'::text)::boolean\n            ELSE NULL::boolean\n        END AS quarantined,\n    payload ->> 'availabilityStatus'::text AS availability_status,\n    payload ->> 'acceptableReason'::text AS acceptable_reason,\n    occurred_at,\n    recorded_at,\n    source_path,\n    source_url,\n    payload\n   FROM incept.incept_event_ledger e\n  WHERE event_type = ANY (ARRAY['evaluation.completed'::text, 'quality_bar.evaluated'::text, 'quality_target.missed'::text, 'quality_target.cleared'::text, 'customer_audit.evaluated'::text, 'runtime_matrix.evaluated'::text, 'canonical_visual_grid.evaluated'::text]);",
        "exampleQuery": "select * from incept.incept_quality_grid_fact_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-event-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-loop-run-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-skill-id"
          },
          {
            "name": "content_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Generated artifact type, such as lesson, question, script, or report component.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-content-type"
          },
          {
            "name": "content_subtype",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "More specific generated artifact subtype used for quality grids and model comparisons.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "mastery_gate_question",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-content-subtype"
          },
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-quality-bar-version"
          },
          {
            "name": "subject",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Subject dimension used by quality-grid facts.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "math",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-subject"
          },
          {
            "name": "grade_level",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Grade-level dimension used by quality-grid facts.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-grade-level"
          },
          {
            "name": "input_range_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the input range, cohort, or fixture slice used when calculating this quality-grid fact.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Free identifier scoped by grid dimensions and ledger event; no Platform3 table is the target; nullable=true.",
            "example": "range-platform-dd-incept-fields",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-input-range-id"
          },
          {
            "name": "strict_quality_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_quality_grid_fact_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-strict-quality-score"
          },
          {
            "name": "progress_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_quality_grid_fact_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-progress-score"
          },
          {
            "name": "target_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_quality_grid_fact_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-target-score"
          },
          {
            "name": "target_pass_rate",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Target pass rate required by the quality bar or progress projection.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "0.95",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-target-pass-rate"
          },
          {
            "name": "pass_rate",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Observed pass rate for the quality-grid fact.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "0.97",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-pass-rate"
          },
          {
            "name": "quality_cleared",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean projection flag indicating whether the quality bar cleared for the row or content slice.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-quality-cleared"
          },
          {
            "name": "customer_available",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean projection flag indicating whether generated output is available to the customer-facing path.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-customer-available"
          },
          {
            "name": "quarantined",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean flag indicating generated output is withheld from customer availability.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-quarantined"
          },
          {
            "name": "availability_status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Status value projected by incept_quality_grid_fact_v; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-availability-status"
          },
          {
            "name": "acceptable_reason",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Redacted reason explaining why a quality/progress state is acceptable or not acceptable.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "quality bar passed with two independent reviewers",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-acceptable-reason"
          },
          {
            "name": "occurred_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time the underlying event happened.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-occurred-at"
          },
          {
            "name": "recorded_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time Platform3 recorded the event.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-recorded-at"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-source-url"
          },
          {
            "name": "payload",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Typed event payload. The event schema version defines required keys; direct credentials, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-quality-grid-fact-v-payload"
          }
        ],
        "anchor": "table-incept-incept-quality-grid-fact-v"
      },
      {
        "name": "incept.incept_model_grid_latest_v",
        "relationName": "incept_model_grid_latest_v",
        "title": "Model Grid Latest view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Latest model-grid evidence per grid/task/subtype/provider/model for side-by-side comparison reports.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the projection rule. Raw-DB readers must apply the same tenant/auth/audit guardrails as the API path before returning rows.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT model_grid_evidence_id,\n    event_id,\n    tenant_id,\n    run_id,\n    grid_id,\n    task_id,\n    subtype_id,\n    provider,\n    model_name,\n    evaluator_id,\n    quality_bar_id,\n    quality_bar_version,\n    score,\n    passed,\n    latency_ms,\n    cost_usd,\n    artifact_pointer_id,\n    source_path,\n    source_url,\n    result,\n    created_at,\n    recency_rank\n   FROM ( SELECT m.model_grid_evidence_id,\n            m.event_id,\n            m.tenant_id,\n            m.run_id,\n            m.grid_id,\n            m.task_id,\n            m.subtype_id,\n            m.provider,\n            m.model_name,\n            m.evaluator_id,\n            m.quality_bar_id,\n            m.quality_bar_version,\n            m.score,\n            m.passed,\n            m.latency_ms,\n            m.cost_usd,\n            m.artifact_pointer_id,\n            m.source_path,\n            m.source_url,\n            m.result,\n            m.created_at,\n            row_number() OVER (PARTITION BY (COALESCE(m.grid_id, ''::text)), (COALESCE(m.task_id, ''::text)), (COALESCE(m.subtype_id, ''::text)), (COALESCE(m.provider, ''::text)), (COALESCE(m.model_name, ''::text)) ORDER BY m.created_at DESC, m.model_grid_evidence_id DESC) AS recency_rank\n           FROM incept.incept_model_grid_evidence m) ranked\n  WHERE recency_rank = 1;",
        "exampleQuery": "select * from incept.incept_model_grid_latest_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "model_grid_evidence_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected latest model-grid evidence row id for this grid, task, subtype, provider, and model grain.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_model_grid_evidence.model_grid_evidence_id; one latest row per grid/task/subtype/provider/model after recency ranking; nullable=true.",
            "example": "mg-ev-platform3-dd-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-model-grid-evidence-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-event-id"
          },
          {
            "name": "tenant_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Platform tenant that owns this Incept fact and scopes API/view readback.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "does not match the authenticated Platform3 tenant scope",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-tenant-id"
          },
          {
            "name": "run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected model-grid execution run id for the latest evidence row at this comparison grain.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_model_grid_evidence.run_id; soft reference to model-grid run evidence; nullable=true.",
            "example": "model-grid-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-run-id"
          },
          {
            "name": "grid_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected model-grid definition id for the latest evidence row.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_model_grid_evidence.grid_id; soft reference to a grid definition in ledger/source evidence; nullable=true.",
            "example": "platform3-data-dictionary-grid",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-grid-id"
          },
          {
            "name": "task_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected model-grid task id for the latest evidence row.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_model_grid_evidence.task_id; soft reference to a task definition in ledger/source evidence; nullable=true.",
            "example": "describe-incept-reference-fields",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-task-id"
          },
          {
            "name": "subtype_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected subtype slice for the latest model-grid evidence row.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_model_grid_evidence.subtype_id; soft reference to a subtype slice in grid evidence; nullable=true.",
            "example": "reference-field-docs",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-subtype-id"
          },
          {
            "name": "provider",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "AI provider or execution provider that produced model-grid evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "openai",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-provider"
          },
          {
            "name": "model_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Model identifier used for a generation or evaluation run.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "gpt-5-codex",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-model-name"
          },
          {
            "name": "evaluator_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the evaluator, grader, or judge configuration that produced model-grid evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "rubric-judge-platform-dd",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-evaluator-id"
          },
          {
            "name": "quality_bar_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Quality bar identifier applied to the event, evidence row, or projection.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "qb-platform-dd-field-coverage",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-quality-bar-id"
          },
          {
            "name": "quality_bar_version",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Version of the quality bar definition used for scoring or gating.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-quality-bar-version"
          },
          {
            "name": "score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Numeric score produced by an evaluator or quality gate.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-score"
          },
          {
            "name": "passed",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean result of a quality, model-grid, layer-health, or projection check.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-passed"
          },
          {
            "name": "latency_ms",
            "type": "integer(32)",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Measured latency in milliseconds for a model-grid task or evaluation.",
            "constraints": "Nullable integer(32) column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-latency-ms"
          },
          {
            "name": "cost_usd",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Estimated task cost in US dollars for model-grid comparison.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-cost-usd"
          },
          {
            "name": "artifact_pointer_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected artifact pointer id for the latest model-grid output or judge evidence.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_model_grid_evidence.artifact_pointer_id; many latest rows may reference one incept_event_artifacts row; nullable=true.",
            "example": "0d4ce2f4-1c42-4f3c-9f0d-03fb7f5271d3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-artifact-pointer-id"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-source-url"
          },
          {
            "name": "result",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Typed evaluation result payload for model-grid or quality evidence.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-result"
          },
          {
            "name": "created_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Timestamp when this row was inserted into the governed Incept schema.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-created-at"
          },
          {
            "name": "recency_rank",
            "type": "bigint(64)",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Rank within the latest-model-grid view; rank 1 is the most recent evidence for that grid/task/subtype/provider/model grain.",
            "constraints": "Nullable bigint(64) column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-model-grid-latest-v-recency-rank"
          }
        ],
        "anchor": "table-incept-incept-model-grid-latest-v"
      },
      {
        "name": "incept.incept_customer_feedback_status_v",
        "relationName": "incept_customer_feedback_status_v",
        "title": "Customer Feedback Status view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Customer audit and customer feedback status view with GitHub issue links.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the projection rule. Raw-DB readers must apply the same tenant/auth/audit guardrails as the API path before returning rows.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT cf.feedback_id,\n    cf.evidence_id,\n    cf.status,\n    cf.source_type,\n    cf.severity,\n    cf.expected_blocking,\n    cf.skill_id,\n    cf.loop_id,\n    cf.artifact_id,\n    cf.github_issue_key,\n    eil.external_system,\n    eil.repo,\n    eil.issue_number,\n    eil.url AS issue_url,\n    cf.received_at,\n    cf.source_path,\n    cf.source_url,\n    cf.normalized_payload,\n    cf.redacted_customer,\n    cf.event_id\n   FROM incept.incept_customer_feedback cf\n     LEFT JOIN incept.incept_external_issue_links eil ON eil.external_issue_key = cf.github_issue_key;",
        "exampleQuery": "select * from incept.incept_customer_feedback_status_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "feedback_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected feedback row id used to join customer-feedback status back to normalized source evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_customer_feedback.feedback_id; one status row per feedback item after issue-link joins; nullable=true.",
            "example": "feedback-GH-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-feedback-id"
          },
          {
            "name": "evidence_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected source evidence id for the feedback item.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_customer_feedback.evidence_id; soft reference to source evidence; nullable=true.",
            "example": "evidence-platform3-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-evidence-id"
          },
          {
            "name": "status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-status"
          },
          {
            "name": "source_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Type of source evidence, such as GitHub issue, customer audit, operator note, or generated report.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "github_issue",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-source-type"
          },
          {
            "name": "severity",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Severity label assigned to customer feedback or issue evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "blocking",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-severity"
          },
          {
            "name": "expected_blocking",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean indicating whether the feedback is expected to block promotion or release.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-expected-blocking"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-skill-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-loop-id"
          },
          {
            "name": "artifact_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Generated or evaluated artifact identifier from the producer workflow.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "artifact-platform-dd-index-html",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-artifact-id"
          },
          {
            "name": "github_issue_key",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Stable GitHub issue key used to connect feedback/status views to the external issue tracker.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "GH-148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-github-issue-key"
          },
          {
            "name": "external_system",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External tracker or system linked to the Incept evidence, such as GitHub.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "github",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-external-system"
          },
          {
            "name": "repo",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository owner/name associated with an external issue or source evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "andymontgomery-byte/platform3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-repo"
          },
          {
            "name": "issue_number",
            "type": "integer(32)",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Numeric issue identifier in the external tracker.",
            "constraints": "Nullable integer(32) column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "148",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-issue-number"
          },
          {
            "name": "issue_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "URL evidence for incept_customer_feedback_status_v. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-issue-url"
          },
          {
            "name": "received_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time the customer feedback or issue evidence was received by the governed Incept pipeline.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-received-at"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-source-url"
          },
          {
            "name": "normalized_payload",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Redacted normalized JSON payload for feedback or customer evidence after source-specific parsing.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-normalized-payload"
          },
          {
            "name": "redacted_customer",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Redacted customer identity/context object. It must not contain direct PII or credentials.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-redacted-customer"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-customer-feedback-status-v-event-id"
          }
        ],
        "anchor": "table-incept-incept-customer-feedback-status-v"
      },
      {
        "name": "incept.incept_layer_health_v",
        "relationName": "incept_layer_health_v",
        "title": "Layer Health view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Layer health and five-layer supervisor status facts for owner/manager reporting.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the projection rule. Raw-DB readers must apply the same tenant/auth/audit guardrails as the API path before returning rows.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT event_id,\n    loop_run_id,\n    event_type,\n    COALESCE(payload ->> 'layerId'::text, payload ->> 'ownerLayer'::text) AS layer_id,\n    COALESCE(payload ->> 'ownerId'::text, payload ->> 'primaryOwner'::text) AS owner_id,\n    COALESCE(payload ->> 'managerId'::text, payload ->> 'factoryManager'::text) AS manager_id,\n    payload ->> 'status'::text AS status,\n        CASE\n            WHEN lower(payload ->> 'passed'::text) = ANY (ARRAY['true'::text, 'false'::text]) THEN (payload ->> 'passed'::text)::boolean\n            ELSE NULL::boolean\n        END AS passed,\n        CASE\n            WHEN (payload ->> 'score'::text) ~ '^-?[0-9]+(\\.[0-9]+)?$'::text THEN (payload ->> 'score'::text)::numeric\n            ELSE NULL::numeric\n        END AS score,\n    payload -> 'checks'::text AS checks,\n    payload -> 'failures'::text AS failures,\n    occurred_at,\n    recorded_at,\n    source_path,\n    source_url,\n    payload\n   FROM incept.incept_event_ledger e\n  WHERE event_type = ANY (ARRAY['layer.health.checked'::text, 'five_layer.supervisor.completed'::text, 'factory.repair_intake.completed'::text, 'issue.routing.completed'::text]);",
        "exampleQuery": "select * from incept.incept_layer_health_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-event-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-loop-run-id"
          },
          {
            "name": "event_type",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Governed event label that names what happened in the generation loop.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "incept.producer_surface.registered",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-event-type"
          },
          {
            "name": "layer_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the supervised layer, product area, or platform surface whose health is being reported.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Free identifier scoped by the layer-health event and report policy; no Platform3 table is the target; nullable=true.",
            "example": "platform-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-layer-id"
          },
          {
            "name": "owner_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Pseudonymous owner identifier for the layer health row.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Free pseudonymous identifier from the layer-health payload; no People & Orgs person row is implied; nullable=true.",
            "example": "owner:platform-architecture",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-owner-id"
          },
          {
            "name": "manager_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Pseudonymous manager or reviewer identifier for the layer health row.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Free pseudonymous identifier from the layer-health payload; no People & Orgs person row is implied; nullable=true.",
            "example": "manager:platform-loop",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-manager-id"
          },
          {
            "name": "status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Lifecycle state for this Incept table. Allowed values are constrained by the table-specific CHECK constraint.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-status"
          },
          {
            "name": "passed",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean result of a quality, model-grid, layer-health, or projection check.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-passed"
          },
          {
            "name": "score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Numeric score produced by an evaluator or quality gate.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-score"
          },
          {
            "name": "checks",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Structured check results used by layer-health projections.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-checks"
          },
          {
            "name": "failures",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Structured failure list used by layer-health projections.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-failures"
          },
          {
            "name": "occurred_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time the underlying event happened.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-occurred-at"
          },
          {
            "name": "recorded_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time Platform3 recorded the event.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-recorded-at"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-source-url"
          },
          {
            "name": "payload",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Typed event payload. The event schema version defines required keys; direct credentials, JWTs, raw customer PII, IP addresses, and user agents are not allowed.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-layer-health-v-payload"
          }
        ],
        "anchor": "table-incept-incept-layer-health-v"
      },
      {
        "name": "incept.incept_promotion_timeline_v",
        "relationName": "incept_promotion_timeline_v",
        "title": "Promotion Timeline view",
        "kind": "view",
        "sourceClass": "Incept governed view",
        "purpose": "Promotion, deployment, and release decision timeline for skill/version reporting.",
        "lifecycle": "Read-only projection over governed Incept rows. It is rebuilt from backing ledger/index facts; consumers must not persist a private copy as product truth.",
        "primaryKey": "Read-only projection grain; see projection rule and view definition.",
        "relationships": [
          "Read-only projection over the governed Incept tables; relationships are inherited from the view definition."
        ],
        "constraints": [
          "Read-only view; constraints are inherited from source tables."
        ],
        "indexes": [
          "No physical index; query plans use the underlying source tables."
        ],
        "projectionRules": [
          "Read-only Platform3 projection: consumers may read this shape through the governed API/view path, but may not write to it.",
          "The view definition below is the projection rule. Raw-DB readers must apply the same tenant/auth/audit guardrails as the API path before returning rows.",
          "If a projected value disagrees with its source ledger row, the ledger row and linked typed index tables are the backing facts to reconcile."
        ],
        "viewDefinition": " SELECT pd.promotion_decision_id,\n    pd.event_id,\n    pd.loop_run_id,\n    pd.loop_id,\n    pd.skill_id,\n    pd.baseline_version_id,\n    pd.candidate_version_id,\n    pd.candidate_eval_run_id,\n    pd.previous_best_score,\n    pd.candidate_score,\n    pd.accepted,\n    pd.decision_status,\n    pd.decided_at,\n    pd.actor_subject,\n    pd.decision_reason,\n    pd.ai_oversight,\n    pd.deployment_id,\n    d.environment AS deployment_environment,\n    d.status AS deployment_status,\n    d.deployed_at,\n    d.deployment_url,\n    e.branch_name,\n    e.commit_sha,\n    e.pull_request_url,\n    pd.source_path,\n    pd.source_url,\n    pd.result_payload\n   FROM incept.incept_promotion_decisions pd\n     JOIN incept.incept_event_ledger e ON e.event_id = pd.event_id\n     LEFT JOIN incept.incept_deployments d ON d.deployment_id = pd.deployment_id;",
        "exampleQuery": "select * from incept.incept_promotion_timeline_v where tenant_id = $1 order by recorded_at desc limit 50;",
        "fields": [
          {
            "name": "promotion_decision_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected promotion decision id for this promotion/deployment timeline row.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projection of incept_promotion_decisions.promotion_decision_id; one timeline row per promotion decision plus deployment join; nullable=true.",
            "example": "promotion-platform3-148-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-promotion-decision-id"
          },
          {
            "name": "event_id",
            "type": "uuid",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Canonical Incept event identifier. In typed tables it links the index row back to the ledger event; in views it identifies the projected ledger fact.",
            "constraints": "Nullable uuid column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2ddf4a76-c2fb-4c27-bc2e-bf04ddfdf36b",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-event-id"
          },
          {
            "name": "loop_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Run envelope identifier that groups ledger events emitted by one daemon, global, backfill, or per-loop execution.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop-run-2026-06-25-001",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-loop-run-id"
          },
          {
            "name": "loop_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Identifier for the generation loop, skill, or content track being evaluated or repaired.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-data-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-loop-id"
          },
          {
            "name": "skill_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Skill identifier affected by the generation/evaluation/repair event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-skill-id"
          },
          {
            "name": "baseline_version_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected baseline version id used in the promotion comparison.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only soft reference to the baseline version recorded in promotion evidence; nullable=true.",
            "example": "baseline-version-platform-dd-a2",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-baseline-version-id"
          },
          {
            "name": "candidate_version_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected candidate version id evaluated by the promotion decision.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only soft reference to the candidate version recorded in promotion evidence; nullable=true.",
            "example": "candidate-version-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-candidate-version-id"
          },
          {
            "name": "candidate_eval_run_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected evaluation-run id supporting the promotion decision.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only soft reference to the evaluation run recorded in promotion evidence; nullable=true.",
            "example": "eval-run-platform-dd-a3",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-candidate-eval-run-id"
          },
          {
            "name": "previous_best_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_promotion_timeline_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-previous-best-score"
          },
          {
            "name": "candidate_score",
            "type": "numeric",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Score value used by incept_promotion_timeline_v; units and target semantics come from the linked quality bar or evaluation payload.",
            "constraints": "Nullable numeric column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "1",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-candidate-score"
          },
          {
            "name": "accepted",
            "type": "boolean",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Boolean promotion decision result: true means the candidate was accepted by policy or oversight.",
            "constraints": "Nullable boolean column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "true",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-accepted"
          },
          {
            "name": "decision_status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Status value projected by incept_promotion_timeline_v; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-decision-status"
          },
          {
            "name": "decided_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time a promotion or repair decision was made.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-decided-at"
          },
          {
            "name": "actor_subject",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Pseudonymous subject for the actor; do not store credentials, JWTs, or direct customer PII here.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "agent:codex:data-dictionary-doer",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-actor-subject"
          },
          {
            "name": "decision_reason",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Redacted reason for a promotion decision, suitable for audit and customer-facing status reports.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "candidate met the published quality bar and materialized Content/QTI rows",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-decision-reason"
          },
          {
            "name": "ai_oversight",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "JSON evidence of AI oversight, reviewer reasoning, or automated promotion review.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-ai-oversight"
          },
          {
            "name": "deployment_id",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected deployment id joined into the promotion timeline.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only soft reference to incept_deployments.deployment_id; nullable=true.",
            "example": "deploy-platform3-preview-20260625",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-deployment-id"
          },
          {
            "name": "deployment_environment",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Projected deployment environment joined into the promotion timeline view.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "production",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-deployment-environment"
          },
          {
            "name": "deployment_status",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Status value projected by incept_promotion_timeline_v; allowed values and lifecycle behavior are inherited from the backing table or view definition.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "running",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-deployment-status"
          },
          {
            "name": "deployed_at",
            "type": "timestamptz",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Time deployment evidence says the candidate was deployed or rolled back.",
            "constraints": "Nullable timestamptz column. Timestamp values are stored as PostgreSQL timestamptz and interpreted in UTC. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "2026-06-25T22:18:23Z",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-deployed-at"
          },
          {
            "name": "deployment_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "URL evidence for incept_promotion_timeline_v. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-deployment-url"
          },
          {
            "name": "branch_name",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Git branch associated with the event or deployment evidence.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "platform3-148-incept-dictionary",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-branch-name"
          },
          {
            "name": "commit_sha",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Git commit SHA tied to the event, repair, promotion, or deployment.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-commit-sha"
          },
          {
            "name": "pull_request_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Pull request URL linked to a repair, promotion, or deployment event.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-pull-request-url"
          },
          {
            "name": "source_path",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Repository or storage path for source evidence. It is not a substitute for canonical Content/QTI materialization.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "loop/context/incept-platform3-surface-decision.md",
            "invalidWhen": "not aligned to the object purpose, projection rule, or PITD-032 producer-surface boundary",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-source-path"
          },
          {
            "name": "source_url",
            "type": "text",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "External URL for source evidence. It must not contain credentials or secret-bearing query strings.",
            "constraints": "Nullable text column. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "https://github.com/andymontgomery-byte/platform3/issues/148",
            "invalidWhen": "contains credential-bearing query strings",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-source-url"
          },
          {
            "name": "result_payload",
            "type": "jsonb",
            "required": false,
            "default": null,
            "key": "Projected field",
            "meaning": "Typed result payload for repair, promotion, or deployment evidence.",
            "constraints": "Nullable jsonb column. Must be a JSON value whose business meaning is stated by the object purpose; secrets, JWTs, raw customer PII, IP addresses, and user agents are not allowed. Projected read-only field; do not write directly to this view.",
            "allowedValues": null,
            "relationship": "Read-only projected relationship; follow the view definition to the backing ledger/index rows.",
            "example": "{\"source\":\"incept\",\"redacted\":true}",
            "invalidWhen": "contains secrets, JWTs, raw customer PII, IP addresses, user agents, or non-object JSON when a CHECK requires object shape",
            "edgeCases": "PITD-032 makes direct database reads deprecated bootstrap only. Product consumers read this through Platform3 API/view paths; student-facing generated artifacts still need canonical Content/QTI materialization or explicit reconciliation errors.",
            "provenance": {
              "label": "Incept producer surface",
              "basis": "PITD-032 requires data-dictionary coverage for every listed Incept table/view/field/projection rule.",
              "itd": "https://platform3-andymontgomery-9773s-projects.vercel.app/platform/1edtech/architecture#pitd-032-incept-producer-surface"
            },
            "anchor": "field-incept-incept-promotion-timeline-v-result-payload"
          }
        ],
        "anchor": "table-incept-incept-promotion-timeline-v"
      }
    ],
    "rules": [
      "Incept is a Platform3 upstream producer surface, not a consumer API surface and not an alternate Content/Results/Events/Analytics model.",
      "Every student-facing generated artifact referenced by Incept rows must materialize as canonical Content/QTI rows or carry an explicit reconciliation error.",
      "Consumer-facing Incept progress/status reads go through Platform3 API/view paths with normal auth, tenant scope, audit, data-dictionary coverage, and non-service-role readback.",
      "Incept producer events use incept_traffic_class values in payload. Headline customer Accuracy counts only trafficClass=customer; owner-directed materialization traffic must be goal-run, loop self-tests must be self-test, and missing legacy values default to customer only for backward compatibility.",
      "The Platform3 Incept progress API is the canonical customer-progress read model for contractId=incept-customer-progress-v1 and projectionName=generation-loop-progress-report; omitting contractId/projectionName defaults to this compact customer-progress read model, and it exposes the denominator/detail fields needed to render customer progress without direct SUPABASE_DB_URL access.",
      "The same Platform3 Incept progress API is the canonical customer-generation repair-evidence read model for contractId=incept-customer-generation-ledger-v1; it exposes redacted scope and failure details needed by progress counts and automated repair loops without exposing raw artifacts, and raw repair-evidence API reads must include at least one narrowing filter plus a bounded limit.",
      "GET /platform/producer-surfaces/incept/quality-verdicts/{qualityBarId} is the canonical hosted verdict for a named producer quality bar. It delegates to governed Incept ledger/projection evidence and returns passed, failed, or pending; absent evidence is pending with nullReason=source_missing, never a 404 or inferred pass.",
      "public.incept_generation_runs is legacy/bootstrap compatibility only; no new durable public.incept_* tables may be added.",
      "PostgREST schema exposure alone is not the product contract unless it sits behind Platform3 auth, tenant scope, audit, and this dictionary."
    ],
    "convergenceQuery": "-- Raw-DB input for an Incept customer progress/status answer. Apply JWT tenant scope first.\n-- This mirrors the Platform API's materialized customer-progress fast path.\nselect e.event_id, e.tenant_id, e.loop_run_id, e.loop_id, e.skill_id,\n       e.content_type, e.content_subtype, e.quality_bar_id, e.quality_bar_version,\n       e.event_type, e.payload ->> 'status' as event_status,\n       e.payload ->> 'projectionStatus' as projection_status,\n       coalesce(nullif(e.payload ->> 'trafficClass', ''), nullif(e.payload ->> 'traffic_class', ''), 'customer') as traffic_class,\n       e.payload ->> 'currentScore' as current_score,\n       e.payload ->> 'targetScore' as target_score,\n       e.payload ->> 'customerAvailable' as customer_available,\n       e.payload ->> 'qualityCleared' as quality_cleared,\n       e.occurred_at, e.recorded_at,\n       e.payload ->> 'contractId' as contract_id,\n       e.payload ->> 'projectionName' as projection_name,\n       e.payload ->> 'title' as title,\n       e.payload ->> 'skillTitle' as skill_title,\n       e.payload ->> 'blockingReason' as blocking_reason,\n       e.payload ->> 'reason' as reason,\n       e.payload ->> 'status' as status,\n       e.payload ->> 'failureReason' as failure_reason,\n       e.payload ->> 'feedback' as feedback,\n       e.payload ->> 'feedbackSummary' as feedback_summary,\n       e.payload -> 'failedCheckIds' as failed_check_ids,\n       e.payload ->> 'reviewerConfidence' as reviewer_confidence,\n       e.payload ->> 'capabilityGridNumerator' as capability_grid_numerator,\n       e.payload ->> 'capabilityGridDenominator' as capability_grid_denominator,\n       e.payload ->> 'accuracyEventNumerator' as accuracy_event_numerator,\n       e.payload ->> 'accuracyEventDenominator' as accuracy_event_denominator,\n       e.payload ->> 'heldOutNumerator' as held_out_numerator,\n       e.payload ->> 'heldOutDenominator' as held_out_denominator\nfrom incept.incept_event_ledger e\nwhere e.payload ->> 'contractId' = 'incept-customer-progress-v1'\n  and e.payload ->> 'projectionName' = 'generation-loop-progress-report'\norder by e.occurred_at asc, e.recorded_at asc, e.event_id asc;\n\n-- Raw-DB input for Incept automated repair evidence. Apply JWT tenant scope first.\n-- API callers must provide at least one narrowing filter for this raw repair-evidence contract\n-- (for example eventType, subject, gradeLevel, contentType, contentSubtype, skillId, loopId,\n-- occurredSince, or occurredUntil) and a bounded limit before payload details are extracted.\nselect p.*, e.payload ->> 'contractId' as contract_id,\n       e.payload ->> 'subject' as subject,\n       e.payload ->> 'gradeLevel' as grade_level,\n       e.payload ->> 'grade' as grade,\n       e.payload ->> 'contentType' as content_type,\n       e.payload ->> 'contentSubtype' as content_subtype,\n       coalesce(nullif(e.payload ->> 'trafficClass', ''), nullif(e.payload ->> 'traffic_class', ''), 'customer') as traffic_class,\n       e.payload -> 'dimensionVector' as dimension_vector,\n       e.payload ->> 'status' as status,\n       e.payload ->> 'failureReason' as failure_reason,\n       e.payload ->> 'feedback' as feedback,\n       e.payload ->> 'feedbackSummary' as feedback_summary,\n       e.payload -> 'failedCheckIds' as failed_check_ids,\n       e.payload ->> 'reviewerConfidence' as reviewer_confidence,\n       e.payload ->> 'accuracyEventNumerator' as accuracy_event_numerator,\n       e.payload ->> 'accuracyEventDenominator' as accuracy_event_denominator,\n       e.payload ->> 'currentScore' as current_score,\n       e.payload ->> 'targetScore' as target_score\nfrom incept.incept_progress_projection_input_v p\njoin incept.incept_event_ledger e on e.event_id = p.event_id\nwhere e.payload ->> 'contractId' = 'incept-customer-generation-ledger-v1'\n  and p.event_type = 'evaluation.completed'\n  and coalesce(p.content_type, e.payload ->> 'contentType') = 'image'\n  and p.occurred_at >= timestamptz '2026-01-01T00:00:00Z'\norder by p.occurred_at asc, p.recorded_at asc, p.event_id asc;\n\n-- Reproduce projection freshness from the checkpoint watermark.\nselect projection_name, projection_version, checkpoint_key, last_event_id,\n       source_event_count, materialized_at, status, watermark\nfrom incept.incept_projection_checkpoints\nwhere projection_name = 'generation-loop-progress-report';"
  }
}
