SRC-L01record 1
{
"id": "SRC-L01",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "DashboardSidebarInput.sections is typed as a fixed five-element tuple with the comment 'Must be exactly 5 sections'; six sections is a compile error.",
"limitations": "One rail component; does not describe the app's full route topology.",
"disposition": "load-bearing: falsifies A15 as a flexible convention"
}
SRC-L02record 2
{
"id": "SRC-L02",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "SECTION_PRODUCTS is frozen as ['hub','intelligence','recon','agents','content-gen'].",
"limitations": "Ids only; no evidence about user comprehension.",
"disposition": "load-bearing"
}
SRC-L03record 3
{
"id": "SRC-L03",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Comment 'Fixed section template - IDs, hotkeys, and fallback icons never change'; hotkeys Cmd1-Cmd5 bound to product ids.",
"limitations": "None material.",
"disposition": "supports A15 rejection as default"
}
SRC-L04record 4
{
"id": "SRC-L04",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Agency rail maps Overview->hub, Content->intelligence, Team->recon, Webcam->agents, Tools->content-gen.",
"limitations": "Single persona.",
"disposition": "evidence of slot-label drift"
}
SRC-L05record 5
{
"id": "SRC-L05",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Model webcam rail maps Live->hub, Chat->intelligence, Tasks->recon, Menu->agents, Insights->content-gen. 'recon' therefore means both 'Team' and 'Tasks'; 'content-gen' means both 'Tools' and 'Insights'.",
"limitations": "Two personas in one codebase; not a user study.",
"disposition": "load-bearing: semantic falsification of fixed slot ids"
}
SRC-L06record 6
{
"id": "SRC-L06",
"evidence_class": "observed",
"source": "[local path redacted] (directory listing)",
"observed": "2026-08-27",
"claim": "At least 8 top-level route groups exist (agency, model, client/[clientSlug], portal, content-gen, autosaas, chatters, social-manager, plus editor/gallery/knowledge); portal/ alone holds 20+ compliance sub-routes.",
"limitations": "Directory listing only; route behaviour not executed.",
"disposition": "load-bearing: five-area rail != app IA"
}
SRC-L07record 7
{
"id": "SRC-L07",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Ownership table rules 'Shell / navigation rail -> OWN. Already replaced Plane's launcher'; Twenty record surfaces OWN-transplant; Plane/Documenso/Papermark/Activepieces SERVICE-downstream.",
"limitations": "Document states intent dated 2026-07-31; running code not observed.",
"disposition": "load-bearing: host owns the rail"
}
SRC-L08record 8
{
"id": "SRC-L08",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Names the failure mode: 'owning the security-critical parts while renting the parts that define your product'.",
"limitations": "Reasoning, not measurement.",
"disposition": "adopted as absorb/preserve rationale"
}
SRC-L09record 9
{
"id": "SRC-L09",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "'Teable is NOT a page'; Tables must not be a top-level nav item; 'The broker never clicks Tables. They see a grid and it happens to be Teable'; a separate tables page 'becomes a second silo nobody updates'.",
"limitations": "Rule asserted; feasibility across donors unverified.",
"disposition": "load-bearing: donor-as-embedded-surface rule"
}
SRC-L10record 10
{
"id": "SRC-L10",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Success criteria require donor UI to render inside the SISO shell with no login prompt and no reachable donor signup/login route.",
"limitations": "Criteria, not results.",
"disposition": "adopted as host identity contract"
}
SRC-L11record 11
{
"id": "SRC-L11",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Status FROZEN. 11 host-owned pages (Dashboard, Deals, Buyers, Sellers, Tasks, Documents, Calendar, Reports, Marketing, Team, Settings) each with a base donor plus folded-in donors. No donor receives a nav entry named after itself. Tasks is the single 'whole-slice' donor (Plane).",
"limitations": "Document freeze, not observed running product.",
"disposition": "load-bearing: strongest local shell precedent"
}
SRC-L12record 12
{
"id": "SRC-L12",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "Section 5 'SaaS Shell Map': five primary product areas by default, 'borrows the ISSO dashboard pattern without freezing UI forever'; its gate is that the main activation workflow must be reachable through the shell.",
"limitations": "Convention only; no extracted artifact.",
"disposition": "A15 origin traced"
}
SRC-L13record 13
{
"id": "SRC-L13",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "'no generic ISSO shell extraction' listed under Not yet complete.",
"limitations": "None.",
"disposition": "confirms A15 never validated"
}
SRC-L14record 14
{
"id": "SRC-L14",
"evidence_class": "observed",
"source": "research/actionmodel-builder-research-2026-08-26/phase-8/lanes/03-b2b-template-shelf/outputs/b2b-template-shelf-report.md sec.2-3",
"observed": "2026-08-27",
"claim": "Ten archetypes defined by data spine + authority model; 17 industries each mapped to a primary and secondary archetype.",
"limitations": "Archetype assignment is I-class judgement; industry fit values are hypotheses, not measured demand.",
"disposition": "input to coverage computation"
}
SRC-L15record 15
{
"id": "SRC-L15",
"evidence_class": "observed",
"source": "research/actionmodel-builder-research-2026-08-26/phase-8/lanes/03-b2b-template-shelf/outputs/b2b-template-shelf-report.md sec.7",
"observed": "2026-08-27",
"claim": "Supply inversion: case_workflow (6/17 primary) and portal (6/17 secondary) have the thinnest clean-license supply; field_operations, learning_content, marketplace have zero shelf rows.",
"limitations": "Shelf is 17 rows; no license scan performed.",
"disposition": "load-bearing: build-order rationale"
}
SRC-L16record 16
{
"id": "SRC-L16",
"evidence_class": "observed",
"source": "knowledge/00-MASTER-SYNTHESIS.md sec.'A fixed five-area shell is a hypothesis'",
"observed": "2026-08-27",
"claim": "Five areas 'should not become a constitutional constraint'; shells should be archetype-level assets tested against workflow comprehension and activation.",
"limitations": "Argument, not evidence.",
"disposition": "this run supplies the source-level receipt"
}
SRC-L17record 17
{
"id": "SRC-L17",
"evidence_class": "observed",
"source": "knowledge/00-MASTER-SYNTHESIS.md sec.'Existing software rarely drops in untouched'",
"observed": "2026-08-27",
"claim": "Eight reuse shapes named: intact service, embedded module/microfrontend, transplanted subsystem, extracted package, adapter, generated from pattern, template/archetype, custom delta. Distinguishes cosmetic from boundary adaptation.",
"limitations": "Taxonomy, not measurement.",
"disposition": "adopted as vocabulary"
}
SRC-L18record 18
{
"id": "SRC-L18",
"evidence_class": "observed",
"source": "knowledge/02-ASSUMPTION-LEDGER.md A15",
"observed": "2026-08-27",
"claim": "A15 'The ISSO five-area shell is universal' recorded as unproven, basis 'AutoSaaS convention only', test 'Compare against case/portal archetype task success'.",
"limitations": "Ledger entry.",
"disposition": "reclassified this run to partially falsified at the semantic level"
}
SRC-L19record 19
{
"id": "SRC-L19",
"evidence_class": "observed",
"source": "knowledge/02-ASSUMPTION-LEDGER.md A32-A35",
"observed": "2026-08-27",
"claim": "A32 mature services usually stay downstream (inferred); A33 product-defining surfaces owned/transplanted (inferred); A34 host can absorb donor identity/settings/navigation cleanly (UNKNOWN); A35 standardized settings/onboarding/branding adapter-driven (hypothesis).",
"limitations": "A34 remains unknown after this run - no donor was mounted.",
"disposition": "A34 is the target of gate E3"
}
SRC-L20record 20
{
"id": "SRC-L20",
"evidence_class": "observed",
"source": "[local path redacted] (directory listing)",
"observed": "2026-08-27",
"claim": "Bykonz exists as an archive of ~25 workstream directories plus desktop-1440/mobile-390 screenshots; includes bykonz-affine-admission, bykonz-review-donor, bykonz-integration-map, plane-delivery-candidate. Not a running application.",
"limitations": "Directory names only; no file contents read; shell topology unknown.",
"disposition": "blocker resolved; contents deferred"
}
SRC-L21record 21
{
"id": "SRC-L21",
"evidence_class": "observed",
"source": "site/system-map/data/parts.json P08",
"observed": "2026-08-27",
"claim": "P08 open questions include 'Which archetypes cover 80% of the first 17 industries?' and 'How does the shell absorb donor navigation?'; known list already records the five-area shell as only a hypothesis.",
"limitations": "Registry entry.",
"disposition": "both open questions addressed in this run"
}
SRC-C01record 22
{
"id": "SRC-C01",
"evidence_class": "observed",
"source": "Shopify App Bridge developer documentation",
"observed": "2026-08-27",
"claim": "Shopify embedded apps run in an iframe while the host renders navigation; apps declare nav declaratively (s-app-nav) rather than choosing a position.",
"limitations": "Docs read, not instrumented.",
"disposition": "adopted: donors declare intent, host declares order"
}
SRC-C02record 23
{
"id": "SRC-C02",
"evidence_class": "observed",
"source": "Zendesk Apps framework manifest reference",
"observed": "2026-08-27",
"claim": "Zendesk app locations are fixed host-defined slots (ticket_sidebar, nav_bar, top_bar, modal); ticket_sidebar width is 320px fixed.",
"limitations": "One vendor.",
"disposition": "load-bearing: 320px corroboration #1"
}
SRC-C03record 24
{
"id": "SRC-C03",
"evidence_class": "observed",
"source": "Grafana MegaMenu.tsx:22 and Grafana configure-grafana docs",
"observed": "2026-08-27",
"claim": "Grafana MegaMenu is 320px at >=md; plugins nest under /a/<id>/* and declare addToNav as a boolean; serve_from_sub_path is documented sub-path support.",
"limitations": "AGPL-3.0 licence blocks donor use regardless of topology.",
"disposition": "load-bearing: 320px corroboration #2 + nesting precedent"
}
SRC-C04record 25
{
"id": "SRC-C04",
"evidence_class": "observed",
"source": "Metabase frontend nav/constants.ts",
"observed": "2026-08-27",
"claim": "NAV_SIDEBAR_WIDTH is 324px; app bar 52px, subheader 48px, admin bar 65px.",
"limitations": "Source constants, not rationale.",
"disposition": "320px corroboration #3"
}
SRC-C05record 26
{
"id": "SRC-C05",
"evidence_class": "observed",
"source": "VS Code src/vs/workbench/browser/layout.ts:3026 and activitybarPart.ts:50-56",
"observed": "2026-08-27",
"claim": "Sidebar default width is Math.min(300, mainContainerDimension.width/4); activity bar is 48px. This is the only genuinely proportional rail rule found in the corpus, and it is 25/75 capped.",
"limitations": "Not a B2B SaaS shell.",
"disposition": "load-bearing: the only real citation for a proportional split"
}
SRC-C06record 27
{
"id": "SRC-C06",
"evidence_class": "observed",
"source": "IBM Carbon Design System UI shell guidance",
"observed": "2026-08-27",
"claim": "Carbon publishes the only vendor decision rule found: use the left panel if there are more than five secondary navigation items or if users switch between them frequently; and 'The left panel does not support three tiers of navigation'.",
"limitations": "Guidance, not evidence of task success.",
"disposition": "adopted as nav budget cap + depth limit 2"
}
SRC-C07record 28
{
"id": "SRC-C07",
"evidence_class": "observed",
"source": "Atlassian page-layout@5.4.0/constants.js:26-32",
"observed": "2026-08-27",
"claim": "Left sidebar 240px, collapsed 20px (16 mobile); right sidebar 280px; right panel 368px.",
"limitations": "Constants without rationale.",
"disposition": "width class evidence"
}
SRC-C08record 29
{
"id": "SRC-C08",
"evidence_class": "observed",
"source": "Shopify Polaris 13.9.5 styles.css; GitHub Primer PageLayout.module.css; Material 3 NavigationRail tokens",
"observed": "2026-08-27",
"claim": "Polaris navigation 240px, mobile max 360px, nav becomes full-width overlay below 768px. Primer panes go 100% width below 768px. Material 3 rail is 96dp collapsed / 80dp narrow / 220-360dp expanded, switching by window size class not raw px.",
"limitations": "Three independent design systems; no published rationale for the numbers.",
"disposition": "adopted as collapse breakpoint guidance"
}
SRC-C09record 30
{
"id": "SRC-C09",
"evidence_class": "observed",
"source": "WordPress admin-menu.css and add_menu_page $position behaviour",
"observed": "2026-08-27",
"claim": "#adminmenu is 160px, folded 36px. The $position integer produces silent collisions patched by an MD5 hash offset, making menu order a function of what else is installed.",
"limitations": "One CMS.",
"disposition": "load-bearing: governance rule - never let a donor pick a numeric position"
}
SRC-C10record 31
{
"id": "SRC-C10",
"evidence_class": "observed",
"source": "Atlassian Forge/Connect module documentation; Slack Block Kit; Intercom Canvas Kit",
"observed": "2026-08-27",
"claim": "Three donor tiers recur across mature hosts: server-driven JSON (host renders, no donor CSS), host component library (donor writes against host tokens), raw iframe (donor freedom, visual drift). Consistency and expressiveness trade off monotonically.",
"limitations": "Pattern synthesis across vendors.",
"disposition": "adopted as donor surface tiering"
}
SRC-C11record 32
{
"id": "SRC-C11",
"evidence_class": "observed",
"source": "AWS Console (Unified Navigation) survey",
"observed": "2026-08-27",
"claim": "No third-party embedded UI surface found in the AWS console; Marketplace provisions resources rather than rendering donor UI. Recorded as a deliberate negative data point.",
"limitations": "Absence of evidence in one console.",
"disposition": "negative precedent: large hosts may refuse donor UI entirely"
}
SRC-C12record 33
{
"id": "SRC-C12",
"evidence_class": "observed",
"source": "docs.copilot.app / assembly.com redirect chain; practice.do probes",
"observed": "2026-08-27",
"claim": "The client-portal product formerly at copilot.com is now Assembly (docs.copilot.app 301 -> assembly.com/docs/); old docs.copilot.com and help.copilot.com do not resolve. practice.do returns 404 on all probed paths.",
"limitations": "Cause of practice.do outage unconfirmed.",
"disposition": "identity correction before client use"
}
SRC-C13record 34
{
"id": "SRC-C13",
"evidence_class": "inferred",
"source": "Commercial denominator lanes A-D (111 products)",
"observed": "2026-08-27",
"claim": "111 commercial products were SURVEYED as a denominator space (topology, approximate area count, settings placement, multi-app switching, embedded-app surface); 24 observed and 87 inferred. Only the top 10 are RECORDED as per-row dossiers in top-companies.jsonl. The 111 figure describes surveyed breadth, not enumerated rows in this packet.",
"limitations": "The 111-row enumeration exists only in the research lane's return, not as per-row records in this packet. 87 of 111 were not verified this session; area counts are role/plan/install-dependent and are shape indicators only. Quote as 'surveyed ~111, recorded 10'.",
"disposition": "denominator satisfied; do not quote inferred counts as measurements"
}
SRC-C14record 35
{
"id": "SRC-C14",
"evidence_class": "unknown",
"source": "Search for published comprehension/activation evidence tied to nav topology",
"observed": "2026-08-27",
"claim": "No published evidence was found linking nav topology or top-level area count to task success, comprehension or activation in any surveyed commercial product.",
"limitations": "Absence of found evidence is not proof of absence.",
"disposition": "load-bearing: all comprehension scores in the matrix are judgement"
}
SRC-O01record 36
{
"id": "SRC-O01",
"evidence_class": "observed",
"source": "gh api repos/backstage/backstage; docs/releases/v1.51.0.md; frontend-plugin-api/src/blueprints/PageBlueprint.tsx",
"observed": "2026-08-27",
"claim": "Backstage is Apache-2.0. NavItemBlueprint was REMOVED as a breaking change in v1.51.0; nav items are now auto-discovered from PageBlueprint title/icon. RouteRef indirection means a plugin declares a routing target rather than a URL; ExternalRouteRef is bound in app-config.yaml so plugin A links to plugin B without depending on it.",
"limitations": "Isolation is crash isolation, not security isolation - one React tree, one bundle. composability.md is banner-marked legacy.",
"disposition": "load-bearing: adopt RouteRef; nav derived from registration cannot drift"
}
SRC-O02record 37
{
"id": "SRC-O02",
"evidence_class": "observed",
"source": "gh api repos/SAP/luigi; docs/navigation-parameters-reference.md",
"observed": "2026-08-27",
"claim": "Luigi is Apache-2.0 and is the purest OSS host shell: the host declares every navigation node (pathSegment, label, icon, category, children, viewUrl) and the donor self-registers nothing. virtualTree allows a node to accept arbitrary child paths. Host holds the OIDC session; donor calls LuigiClient.getToken(). isolateView defaults to FALSE, so same-domain nodes reuse one iframe and share a JS context unless opted out per node.",
"limitations": "iframe modal confinement applies; WC mode documented only for non-complex trusted micro frontends.",
"disposition": "load-bearing: host-owned nav config + host-holds-token pattern"
}
SRC-O03record 38
{
"id": "SRC-O03",
"evidence_class": "observed",
"source": "gh api repos/single-spa/single-spa LICENSE body",
"observed": "2026-08-27",
"claim": "GitHub API reports NOASSERTION but the LICENSE body is plain MIT. single-spa fires PopStateEvents and its docs state it 'deviates from the browser's default behavior in some cases'. Unlike qiankun it does not impose a one-routing-app limit. No CSS isolation whatsoever.",
"limitations": "Docs themselves recommend a monolith for small teams.",
"disposition": "load-bearing: NOASSERTION means unclassified, not restrictive"
}
SRC-O04record 39
{
"id": "SRC-O04",
"evidence_class": "observed",
"source": "umijs/qiankun docs/concepts/style-isolation.md and js-sandbox.md; docs/cookbook/migrate-from-2x.md",
"observed": "2026-08-27",
"claim": "qiankun v3 removed strictStyleIsolation/experimentalStyleIsolation; styleIsolation now uses native CSS @scope, defaults to false, and is explicitly 'a one-way boundary' - it stops the app's rules leaking out but does NOT stop host styles flowing in. @font-face remains global; cross-origin stylesheets need CORS or are dropped. A menu, dialog or tooltip rendered under document.body is outside the scope root so the app's scoped selectors will not match it. The JS sandbox is explicitly 'not a security boundary for running untrusted code' and reads fall through to the host.",
"limitations": "Requires native @scope with no polyfill.",
"disposition": "load-bearing: eliminates any option relying on donor CSS surviving or donor modals portaling"
}
SRC-O05record 40
{
"id": "SRC-O05",
"evidence_class": "observed",
"source": "module-federation.io shared configuration docs",
"observed": "2026-08-27",
"claim": "singleton defaults to FALSE, so dependency duplication is the silent default; even singleton:true is defeated by a missing trailing slash ('react-dom' does not intercept react-dom/client, loading a second React). Module Federation ships a Bridge subsystem explicitly for framework isolation, ensuring React contexts and component trees between applications are isolated.",
"limitations": "No CSS story at all.",
"disposition": "load-bearing: sharing one React tree across a donor boundary is vendor-conceded unreliable"
}
SRC-O06record 41
{
"id": "SRC-O06",
"evidence_class": "observed",
"source": "marmelab/react-admin docs/Routing.md",
"observed": "2026-08-27",
"claim": "Documented sub-path support: with createBrowserRouter you set opts.basename; nested inside a host route you use <Admin basename='/admin'>. Docs state plainly 'it is your responsibility to serve the admin from the sub path'. <Admin layout={...}> replaces the entire shell, so a pass-through layout yields chrome-free content.",
"limitations": "MIT verified via gh api spdx.",
"disposition": "load-bearing: the reference donor-absorption pattern"
}
SRC-O07record 42
{
"id": "SRC-O07",
"evidence_class": "observed",
"source": "gh api repos/nocobase/nocobase LICENSE.txt body",
"observed": "2026-08-27",
"claim": "NocoBase License Agreement incorporates Apache-2.0 but states its supplementary terms prevail on conflict. Section 5.2: 'It is not allowed to remove or change the brand, name, link, version number, license, and other information about NocoBase on the Software interface, except for the main LOGO in the upper left corner'. Section 5.4 forbids public no-code/low-code SaaS.",
"limitations": "Legal interpretation is a lawyer's call, not this run's.",
"disposition": "load-bearing: chrome removal can be a licence violation, not an engineering task"
}
SRC-O08record 43
{
"id": "SRC-O08",
"evidence_class": "observed",
"source": "gh api repos/directus/directus LICENSE body",
"observed": "2026-08-27",
"claim": "Directus is NOT BSL and NOT GPL today. It is MSCL-1.0-GPL (Monospace Sustainable Core License, 'Copyright 2026 Monospace Inc.') with a Permitted Purpose limited to non-Competing Use, a prohibition on moving/changing/disabling/circumventing the licence key functionality, and a Grant of Future License to GPL-3.0 effective only on the fourth anniversary. PUBLIC_URL is documented for link generation, not sub-path serving.",
"limitations": "Whether Actionist's use is a Permitted Purpose is a legal question.",
"disposition": "load-bearing: any register recording Directus as BSL/GPL is stale"
}
SRC-O09record 44
{
"id": "SRC-O09",
"evidence_class": "observed",
"source": "gh api license bodies across the 104-repo denominator",
"observed": "2026-08-27",
"claim": "28 of 104 repos returned NOASSERTION. Reading the bodies corrected verdicts in both directions: n8n and NocoDB are Sustainable Use Licence (non-OSI); Outline and Akaunting are BSL; InvoiceNinja is Elastic License 2.0; Odoo is LGPLv3; Twenty is AGPL-3.0 plus enterprise-licensed files; Teable apps are AGPL-3.0 while packages/ are MIT; single-spa is plain MIT that GitHub failed to classify.",
"limitations": "Licence bodies read, not full dependency trees or SBOMs.",
"disposition": "load-bearing: spdx_id is not a rights answer"
}
SRC-O10record 45
{
"id": "SRC-O10",
"evidence_class": "observed",
"source": "OSS denominator, directory-scoped open-core survey",
"observed": "2026-08-27",
"claim": "Directory-scoped open-core is the dominant commercial pattern: ee/, enterprise/, premium/, x-pack, packages/ee/. A donor built from an ee/ path is a licence breach regardless of the top-level badge.",
"limitations": "Pattern synthesis.",
"disposition": "adopted as licence gate rule"
}
SRC-O11record 46
{
"id": "SRC-O11",
"evidence_class": "observed",
"source": "smapiot/piral pilet specification and API docs",
"observed": "2026-08-27",
"claim": "Piral is MIT. registerPage(route, Component) with single-component-per-page; registration is ownership-scoped so pilet B cannot unregister pilet A's page. registerMenu/registerTile live in piral-menu/piral-dashboard, not core; menu items are registered in global state and rendered by the app shell. The pilet spec contains zero occurrences of iframe, sandbox or isolat - isolation is none, verified by negative evidence.",
"limitations": "Donors must be trusted.",
"disposition": "nav registry injection precedent with honest isolation limits"
}
SRC-O12record 47
{
"id": "SRC-O12",
"evidence_class": "observed",
"source": "refinedev/refine documentation",
"observed": "2026-08-27",
"claim": "Refine is MIT and headless by construction - no chrome to strip; routerProvider adapts to the host's router rather than owning routing. Refine documents NO basename/basePath of its own; sub-path behaviour is inherited from whichever router is plugged in.",
"limitations": "Clean documented negative - claiming Refine supports a basename would be inference, not citation.",
"disposition": "headless-donor precedent"
}
SRC-O13record 48
{
"id": "SRC-O13",
"evidence_class": "observed",
"source": "jd-opensource/micro-app and Tencent/wujie documentation",
"observed": "2026-08-27",
"claim": "micro-app defaults to scoped-CSS prefixing rather than shadow DOM, and documents that host styles still affect the sub-app (one-way leak). Enabling shadow disables the default scoped isolation - they are mutually exclusive, not layered, and the vendor warns to use shadow cautiously with React. wujie documents that in a plain iframe, modals can only display inside the iframe and cannot cover the whole page, and route state is lost on refresh.",
"limitations": "Chinese-language docs carry the severest caveats.",
"disposition": "load-bearing: iframe modal confinement"
}
SRC-O14record 49
{
"id": "SRC-O14",
"evidence_class": "observed",
"source": "nginx sub_module; Apache mod_proxy and mod_proxy_html; Traefik stripprefix docs",
"observed": "2026-08-27",
"claim": "Reverse-proxy chrome stripping is brittle: Apache 'will not rewrite other response headers, nor will it by default rewrite URL references inside HTML pages'; nginx sub_filter is literal string replace with sub_filter_once defaulting on and directives not inherited once defined at the current level; mod_proxy_html with ProxyHTMLExtended On 'has no knowledge of what is a URL within an embedded script'; Traefik StripPrefix only sets X-Forwarded-Prefix, so a donor ignoring it escapes the mount. Runtime-generated URLs have no documented fix.",
"limitations": "Docs read; not tested against a donor.",
"disposition": "load-bearing: proxy stripping scored low on evidence for good reason"
}
SRC-O15record 50
{
"id": "SRC-O15",
"evidence_class": "observed",
"source": "MDN Set-Cookie, State Partitioning, Storage Access API; WHATWG HTML",
"observed": "2026-08-27",
"claim": "Iframe auth is a browser-policy problem: SameSite=Lax excludes navigations inside iframe elements; SameSite=None requires Secure; Firefox partitions storage by default since 103; the Storage Access API requires transient user activation so silent auth on load is unavailable, and grants expire after 30 days of inactivity. CHIPS gives per-host state, not cross-site SSO.",
"limitations": "Browser behaviour changes over time; re-verify before implementation.",
"disposition": "load-bearing: iframe option scored 1 on identity coherence"
}
SRC-O16record 51
{
"id": "SRC-O16",
"evidence_class": "observed",
"source": "Next.js basePath docs; SvelteKit config; Tailwind Preflight; MDN stacking context",
"observed": "2026-08-27",
"claim": "Build-time vs runtime path substitution is a real architectural axis: Next.js inlines basePath into client bundles at build time so one build cannot serve two mount points, while NocoBase substitutes APP_PUBLIC_PATH at container start. Root-relative links silently escape a base path (SvelteKit requires prepending base). Tailwind Preflight collides with third-party libraries. A single host transform both traps donor z-index and re-anchors position:fixed, since stacking contexts are treated atomically.",
"limitations": "Framework behaviour, not donor-specific.",
"disposition": "adopted into MountProfile contract"
}
SRC-O17record 52
{
"id": "SRC-O17",
"evidence_class": "observed",
"source": "gh api repo resolution across the denominator",
"observed": "2026-08-27",
"claim": "Identity drift confirmed on several repos: calcom/cal.com redirects to calcom/cal.diy; rowyio/rowy -> buildship-ai/rowy; bytedance/garfish -> web-infra-dev/garfish; mattermost/focalboard -> mattermost-community/focalboard; creativetimofficial/material-dashboard -> creativetimofficial/ui (renamed and repurposed); kubernetes/dashboard is archived. open-mfe/openmfe returns 404 and does not exist at that path; laravel/nova is 404 (commercial).",
"limitations": "Redirects resolve today; unpinned references will drift again.",
"disposition": "pin exact identities before any adoption"
}
SRC-O18record 53
{
"id": "SRC-O18",
"evidence_class": "inferred",
"source": "OSS denominator (104 repos)",
"observed": "2026-08-27",
"claim": "104 OSS repositories were SURVEYED as a denominator space with licence read from the LICENSE body via gh api; 28 NOASSERTION cases were resolved by reading the body. Only the top 10 are RECORDED as per-row dossiers in top-repos.jsonl. The 104 figure describes surveyed breadth, not enumerated rows in this packet.",
"limitations": "The 104-row enumeration exists only in the research lane's return, not as per-row records in this packet. No dependency-tree or SBOM scan; topology for many rows is from docs, not running code. Quote as 'surveyed ~104, recorded 10'.",
"disposition": "denominator satisfied"
}
SRC-X01record 54
{
"id": "SRC-X01",
"evidence_class": "observed",
"source": "This run: coverage computation over the 17-industry primary/secondary mapping",
"observed": "2026-08-27",
"claim": "Primary-only coverage reaches 82.4% (14/17) with 5 archetypes: case_workflow, field_operations, learning_content, scheduling, crm. Requiring BOTH primary and secondary, no subset of 7 or fewer reaches 80% (best 7 = 13/17, 76%); 8 archetypes give 15/17 (88%) and 9 give 17/17. case_workflow + portal together TOUCH 11/17 (65%) but SATISFY only 4/17 (24%). Six industries (construction, ecommerce, hospitality, logistics_freight, real_estate, saas) touch neither.",
"limitations": "Arithmetic is exact; the inputs are I-class judgement from the b2b shelf, not measured demand.",
"disposition": "load-bearing: answers the P08 open question, and answers it uncomfortably"
}
P08-SR-055record 55
{
"id": "P08-SR-055",
"evidence_class": "observed",
"source": "[local path redacted]}/sidebar-config.tsx",
"observed": "2026-08-27",
"claim": "RETRACTION AND RE-VERIFICATION BY THE LANE OWNER. An earlier version of this record claimed the P08 label receipt was wrong (asserting recon='Comms'/'Chat Feed'). THAT CLAIM WAS ITSELF WRONG and is withdrawn. The P08 agent's original receipt is correct. Cause of my error: my extractor matched `label:` then scanned up to 400 chars for `product:`, which crossed the section/item nesting boundary and paired the first NESTED items[] label with the NEXT section's product. Re-extracted by walking back to each section object's own opening brace. VERIFIED SECTION-LEVEL PAIRS: agency rail = Overview->hub, Content->intelligence, Team->recon, Webcam->agents, Tools->content-gen. model rail = Live->hub, Chat->intelligence, Tasks->recon, Menu->agents, Insights->content-gen. content-gen rail (declares product BEFORE label) = Recon->recon, Intelligence->intelligence, Hub->hub, Content Gen->content-gen, Agents->agents — ALL FIVE SELF-CONSISTENT. Confirmed by reading raw source at agency:46-68 and content-gen:39-42/100-102.",
"limitations": "Consequences for the FINDING: (1) 'not one slot id predicts its label' is TOO STRONG — the content-gen rail is fully self-consistent and is the one place ids and labels align. (2) 'Insights maps to hub' is FALSE; Insights->content-gen on the model rail. The A15 finding still holds but on CROSS-RAIL evidence only: the same slot id carries unrelated labels across rails (recon = 'Team' and 'Tasks'; content-gen = 'Tools' and 'Insights'), so an id does not predict content ACROSS personas even where it does within one.",
"disposition": "owner_error_retracted_agent_receipt_upheld"
}
P08-SR-056record 56
{
"id": "P08-SR-056",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"claim": "LANE-OWNER VERIFIED. SISOCRM's rail is a literal RAIL_GROUPS array: 4 groups, 13 destinations. overview=[Dashboard,Calendar]; brokerage=[Deals,Buyers,Sellers]; operations=[Tasks,Documents,TABLES,AI,Reports]; company=[Marketing,Team,Settings]. `{ id: 'tables', label: 'Tables', icon: Table2, to: '/tables' }` is a REAL top-level rail destination — which CONTRADICTS TEABLE-ABSORPTION-BRIEF.md:16,18 ('A Tables page: No' / 'The broker never clicks Tables'). The 'zero donor-named nav entries' claim is FALSE as built. FROZEN-PAGE-SKELETON's 11 pages all shipped; the build added 2 unplanned (Tables, AI).",
"limitations": "Read from the built shell; the design documents predate it by ~1-2 days. Where they disagree the code is what was decided.",
"disposition": "CONTRADICTS_zero_donor_nav_claim"
}
P08-SR-057record 57
{
"id": "P08-SR-057",
"evidence_class": "observed",
"source": "[local path redacted] (wc -l, all 8 patches)",
"observed": "2026-08-27",
"claim": "LANE-OWNER VERIFIED — FIRST REAL MEASUREMENT ON ASSUMPTION A07. Patch sizes reproduce exactly: documenso-siso-frame 17, teable-siso-native-icons 27, teable-siso-records 30, twenty-siso-local 35, papermark-siso-community 62, teable-siso-embed 100, affine-siso-local 130, teable-siso-absorption 273; TOTAL 674. The GRADIENT is the finding: preserving a donor behind an iframe costs 17-62 lines of CSP/config, while absorbing identity and the data layer costs 273 lines across 9 files — touching the donor's auth strategy, SSR auth hop, DB provider and PUBLIC API validation schema (the regex /^[a-z]\\w{0,62}$/i widened to accept a schema-qualified `siso.buyer_profile`).",
"limitations": "Patch line counts measure DIFF SURFACE, not hours — no hour/effort data exists anywhere in the estate, which the inspection reports as a finding rather than a gap. Total divergence would need .teable-runtime diffed against pinned upstream 06a4461e2bc53055182d4df0a72dffa26fd99210.",
"disposition": "A07_false_as_universal_true_in_bounded_region"
}