reality-audit
Reality Audit — spend the tail on the thing that ships
Implementation evidence is easy to collect from the wrong surface: a scratch build, a one-off interpreter run, a test that bypasses the public boundary, plausible printed output. This terminal protocol decides whether the behavior that ships has actually been exercised.
Load it after the final material implementation change, before saying verified, done,
green, or no work remains — and again after an owner correction or a reproduced falsifier
invalidates earlier evidence. Not at task entry, and never interrupt implementation with graph
modelling to prepare for it.
"Checked" is a two-step claim, and the step is always declared. Checking against the record
— look / orient / trace, whether the words agree with what is written — is one step; the
graph is an instrument for observing the world, not the world. Witnessing the world — fresh
observation on the canonical carrier — is the other. Record-checking ranks below world-witnessing,
and behavioral closure is carried by the second only. So when you close anything with the word
"verified", say what you verified it against; a verdict with no named step is not a result. Every
verdict this protocol issues is a world-step verdict.