# Validation register — H1–H11 ## Current H1 autonomous-window prerequisite disposition H1.LOCAL.PREPARE.2026-10-04 / PH0.VAL.C01: **BLOCKED — VALID PREREQUISITE STOP**, neither H1 PASS nor FAIL. Exact local synthetic fixture now has 45 passing author checks, not published gate acceptance. Screenshot corroborates Autoscale/max3, not required max1; credits unverified. Owner approves USD 5 total, included credits only, no extra charges. Required published warm/POST/idle observations remain 0/0/0. H2–H11 UNEXECUTED; full H7, separate review and formal Child closure not claimed. Owner requests PH1–PH3/Governor progression, but dependencies and role activation remain unmet. Evidence: `evidence/phase-0-autonomous-window/h1-local/`; prior evidence unchanged. **v1.1-RC — REVIEW CANDIDATE.** Sources: restored Technical Direction H/B; Architecture §§18/23; Constitution IX; current Owner §§10/18; historical H1 A–O report. ## Shared limits H1 resumption and H2–H11 execution are prohibited in this cut. **Full gate definitions are now restored.** Passing a gate supplies evidence for its bounded decision; it never automatically selects a vendor, authorizes another gate/product/production or freezes architecture. Every proof needs separate valid constitutional cut authority/cost/environment, relevant actual-account evidence and designated review. Only mandatory **H7 validation geography → H1** ordering is established here; no invented chain between H2–H11. | Gate | Purpose | Prerequisites / dependencies | Authorization now | Execution / disposition | Evidence | What PASS establishes / does not authorize | |---|---|---|---|---|---|---| | H1 | Astro/selective React/Node runtime proof in separate synthetic disposable project | H7 validation geography → actual publishing/cost/synthetic environment verification | NOT AUTHORIZED TO RESUME | Historical BLOCKED valid prerequisite stop; not PASS/FAIL/CLOSED | A–O report, ZIP, raw preflight | Required bounded runtime suitability only; no production readiness/product/next gate/freeze | | H2 | CMS choice / publication | Approved isolated proof; editor/content contract; account API/quotas/cost/processor review | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | None of required proof supplied | Structured content/revisions/media/localization, protected draft/preview/publication, outage preservation, release traceability/media dependency; informs CMS choice, not implementation/publication | | H3 | Journal / PostgreSQL / dispatch | Approved isolated proof; minimal atomic acceptance/intent contract; identity/privacy/access and pool/provider limits | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | None of required proof supplied | Commit-before-success, rollback/no false success, ambiguous commits, safe retry/dedup/concurrency, restart/republish persistence, atomic delivery intent and failure recovery, restricted inspection; informs journal/access design, not schema/CRM/product authority | | H4 | Transactional email | Approved controlled proof; account/domain ownership and SPF/DKIM/DMARC; correlated journal-ID delivery contract | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | None of required proof supplied | Rejection/timeout/retry/bounce/duplicate-event visibility and recovery; email cannot invalidate committed acceptance; informs provider design, not setup/spend/guarantees | | H5 | Anti-abuse / shared enforcement | Approved bounded proof; payload/control policy; concurrent/replica-equivalent methodology | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | None of required proof supplied | Bounded payload/shared enforcement, legitimate/shared-network usability, safe logs and dependency-failure policy; no memory-only shared limiter; informs controls, not product exposure | | H6 | Privacy-appropriate analytics | Approved events/processor/cost/privacy configuration and proof | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | None of required proof supplied | Actual requests exclude names/emails/free text/private project/artist data; accepted conversion follows durable acceptance; consent/blocker limits; analytics outside transaction, not acceptance truth or publication permission | | H7 | Validation geography North America approval; production is separate | Explicit validation Owner decision before H1; actual location remains unverified | Historical limited approval reported; NO CURRENT EXECUTION | Validation approval recorded, deployed location NOT DEMONSTRATED; production NOT AUTHORIZED | H1 report A/B/O + preserved prerequisite doc | Limited validation location decision only; not production H7 closure | | H8 | Recovery / coordinated restore | Actual plan/default-configured retention/available history; approved isolated restore/export; Owner-approved RPO/RTO | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | Documentary plan baseline only; no actual restore proof | Recovered inquiries/intent, usable export, application/database compatibility and safe replay; informs recovery reliance, not zero loss/default maximum/production acceptance | | H9 | Secrets / staff access | Approved access inventory and synthetic exposure proof; accountable rotation/recovery owners | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | Historical existence-only preflight, not required access proof | Who views secrets or executes with them, MFA where available, scoped credentials, dev/production separation, exposure controls; not privilege grant or real-secret disclosure | | H10 | CMS export / exit | Approved representative content/metadata/media proof; permissions/account ownership/cost review | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED | None of required proof supplied | Complete usable export/recovery/migration format, media references/files and limitations; informs portability, not selected CMS/frozen architecture | | H11 | Storage boundaries if selected | Explicit justified App Storage selection and approved actual ownership/location/access/export proof | NOT AUTHORIZED | UNEXECUTED / NOT DEMONSTRATED — CONDITIONAL | Project-scoped documentary baseline only | Project ownership/dev-production/public-private boundaries, actual location/export/recovery, no venture sharing; N/A only if later justified without adoption, never automatic PASS | “Not executed in recovered record” is not a claim that no lost historical action ever occurred. Current Owner states no H2–H11 execution should be falsely recorded. H7 now also has direct current Owner confirmation: **North America approved for disposable H1 validation Project only**. Production separately requires intended North America or approved evidence-backed exception and actual compute/database/storage/pre-created-resource/external-processor checks before first publish. Approval of geography is not an executed technical proof. ## Historical H1 requirements and missing observations Preserved historical benchmarks: ≥20 warm route samples, adequate POST samples, route p95 ≤800 ms, POST p95 ≤1 s, ≥10 idle-to-request observations with actual idle/startup classification, no meaningful cold p95 from ten, LCP ≤2.5 s p75 where meaningful, initial content JS ≤100 KB compressed. Report retains functional/security/runtime/no-JS/island/POST/error/secret/header/publication-resilience/accessibility requirements. Actual warm/POST/idle observations: **0 / 0 / 0**. These criteria were not run or waived. ## Restored H1 contract definition — not a resumed cut Technical Direction H1 governs the full future proof: **one synthetic prerendered route, one small selective React island, one mock bounded POST, mock content and a synthetic server-only marker**, separate disposable Project; no brand/product UI, real integrations, database, company/artist/client data or production credentials/CMS/domain. - Supported stable Astro and compatible Node adapter/runtime with reproducible config; clean authorized Autoscale build/start and correct binding/port. - Mock HTML readable before/without JS; only intended island hydrates, keyboard/touch works, no hydration errors. - POST accepts valid bounded input, rejects malformed/oversized input and demonstrates controlled forced failures; invalid input never acceptance success. - Synthetic marker server-readable but absent from HTML/bundles/responses/logs. - Representative success/error headers; tested CSP allows required assets without weakening simply to pass. - Mock approved publication survives source outage; failed new-content build does not replace working publication. - Applicable accessibility/JS/LCP checks, asset sizes/statuses/headers/build/start/forced-error evidence. - Warm route minimum **20 exploratory navigations**, expanded as needed for adequate p95; route p95 **≤800 ms**, POST p95 **≤1 s**, controlled LCP **≤2.5 s p75**, content JS budget. State profile/sample/limits; lab does not prove field CWV. - At least **10 initial idle-to-request observations** with per-result idle duration/startup evidence. Distinguish confirmed cold starts, unconfirmed idle requests and slow requests; report meaningful-cohort median/maximum/distribution. **1.5 s is initial target, not automatic tiny-sample FAIL; no statistically meaningful p95 from ten.** **PASS:** mandatory functional/security/failure/accessibility/JS/LCP checks pass, runtime suitable without material problems; recommend—not self-issue—technology ratification. **PASS WITH ADJUSTMENT:** no mandatory waiver; assess target-exceeding cold/deployment behaviour by user impact, prerender/intake latency, frequency, alternatives and cost; record approved adjustment and required confirming evidence before adoption. **FAIL:** unresolved material functional/security/quality failure or unacceptable measured user impact; preserve reproduction; propose bounded fix/retest or Owner-approved fallback review, never automatic parallel Next.js. Insufficient evidence keeps the conclusion unproven/BLOCKED. Preserve accepted evidence independently before any separately authorized disposal. **Current H1 is BLOCKED — VALID PREREQUISITE STOP, NOT PASS, NOT FAIL, NOT Astro rejection, NOT Replit rejection; runtime NOT DEMONSTRATED.** H1 blockers: no observable actual region/mode/cost or synthetic-only secret provenance; publishing requires user action. This is recorded control-access limitation, not proof of framework failure. No empirical deployment secret synchronization, actual deployed retention, browser behavior, region/performance or CMS controls were demonstrated. Do not rerun checks under this recovery cut.