{
  "schema_id": "https://id.registrystack.org/schemas/registryctl/project-documentation/registry.project.configuration_reference.v1.schema.json",
  "format_version": "1.0",
  "reference_baseline": {
    "generator_lifecycle": "unreleased",
    "published_release": null,
    "field_history_status": "not_verified",
    "history_verification_method": null,
    "compared_releases": []
  },
  "source_contract": {
    "schemas": [
      "project",
      "environment",
      "integration",
      "fixture",
      "entity",
      "relay",
      "notary"
    ],
    "schema_sources": [
      "project.schema.json",
      "environment.schema.json",
      "integration.schema.json",
      "fixture.schema.json",
      "entity.schema.json",
      "registry-relay.config.schema.json",
      "registry-notary.config.schema.json"
    ],
    "field_knowledge": "schemas/project-authoring/parity-coverage.json#field_knowledge",
    "human_intent": "schemas/project-authoring/documentation-intent.json",
    "runtime_intent": [
      "crates/registry-relay/config/documentation-intent.json",
      "crates/registry-notary-core/config/documentation-intent.json"
    ],
    "reads_country_workspaces": false,
    "reads_runtime_configuration": false
  },
  "coverage": {
    "schema_count": 7,
    "path_count": 1771,
    "reference_count": 485,
    "by_schema": {
      "project": 220,
      "environment": 198,
      "integration": 142,
      "fixture": 62,
      "entity": 35,
      "relay": 584,
      "notary": 530
    },
    "by_path_kind": {
      "root": 7,
      "property": 1413,
      "map_key": 25,
      "map_value": 47,
      "array_item": 178,
      "branch": 101
    },
    "by_sensitivity": {
      "public": 16,
      "internal": 1145,
      "sensitive": 399,
      "secret_reference": 41,
      "redacted_fixture": 50,
      "structural": 120
    },
    "by_intent_source": {
      "schema_description": 504,
      "reviewed_override": 248,
      "structural_taxonomy": 127,
      "reviewed_profile": 892
    },
    "by_intent_profile": {
      "notary_audit_internal": 4,
      "notary_audit_secret_reference": 1,
      "notary_audit_sensitive": 2,
      "notary_auth_internal": 13,
      "notary_auth_oidc_scope_map_open_map": 1,
      "notary_auth_secret_reference": 4,
      "notary_auth_sensitive": 95,
      "notary_cel_internal": 14,
      "notary_config_trust_internal": 1,
      "notary_config_trust_sensitive": 4,
      "notary_credential_status_sensitive": 4,
      "notary_deployment_internal": 13,
      "notary_deployment_sensitive": 1,
      "notary_evidence_claims_evidence_mode_consultations_inputs_open_map": 1,
      "notary_evidence_claims_evidence_mode_consultations_open_map": 1,
      "notary_evidence_claims_evidence_mode_consultations_outputs_open_map": 1,
      "notary_evidence_claims_rule_bindings_claims_open_map": 1,
      "notary_evidence_credential_profiles_open_map": 1,
      "notary_evidence_internal": 92,
      "notary_evidence_secret_reference": 5,
      "notary_evidence_sensitive": 40,
      "notary_evidence_signing_keys_open_map": 1,
      "notary_evidence_variables_open_map": 1,
      "notary_federation_internal": 43,
      "notary_federation_secret_reference": 1,
      "notary_federation_sensitive": 5,
      "notary_instance_internal": 5,
      "notary_instance_sensitive": 1,
      "notary_oid4vci_credential_configurations_open_map": 1,
      "notary_oid4vci_internal": 33,
      "notary_oid4vci_sensitive": 48,
      "notary_root_structural": 1,
      "notary_server_internal": 13,
      "notary_server_sensitive": 2,
      "notary_state_internal": 6,
      "notary_state_secret_reference": 2,
      "notary_state_sensitive": 1,
      "notary_subject_access_sensitive": 67,
      "relay_audit_internal": 9,
      "relay_audit_secret_reference": 1,
      "relay_audit_sensitive": 1,
      "relay_auth_internal": 15,
      "relay_auth_oidc_scope_map_open_map": 1,
      "relay_auth_secret_reference": 4,
      "relay_auth_sensitive": 15,
      "relay_catalog_internal": 1,
      "relay_catalog_public": 6,
      "relay_catalog_sensitive": 1,
      "relay_config_trust_internal": 1,
      "relay_config_trust_sensitive": 4,
      "relay_consultation_internal": 26,
      "relay_consultation_secret_reference": 8,
      "relay_consultation_sensitive": 20,
      "relay_datasets_internal": 391,
      "relay_datasets_secret_reference": 1,
      "relay_datasets_sensitive": 7,
      "relay_deployment_internal": 12,
      "relay_deployment_sensitive": 2,
      "relay_instance_internal": 1,
      "relay_instance_public": 4,
      "relay_metadata_internal": 6,
      "relay_metadata_sensitive": 1,
      "relay_root_structural": 1,
      "relay_server_internal": 13,
      "relay_server_sensitive": 5,
      "relay_standards_internal": 18,
      "relay_standards_sensitive": 3,
      "relay_standards_spdci_registries_expression_fields_open_map": 1,
      "relay_standards_spdci_registries_identifiers_open_map": 1,
      "relay_standards_spdci_registries_open_map": 1,
      "relay_standards_spdci_registries_response_fields_open_map": 1,
      "relay_vocabularies_internal": 1,
      "relay_vocabularies_open_map": 1
    }
  },
  "fields": [
    {
      "address": {
        "schema": "project",
        "pointer": "",
        "path_kind": "root"
      },
      "purpose": "Declares the product-neutral Registry Stack project graph: integrations, materialized entities, and Relay or Notary services.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": true
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "version",
            "registry",
            "services"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/access/properties/scopes",
        "path_kind": "property"
      },
      "purpose": "Lists the scopes a caller must hold to use the enclosing evidence service.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/access/properties/scopes/items",
        "path_kind": "array_item"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/claimValue/properties/max_bytes",
        "path_kind": "property"
      },
      "purpose": "Bounds the encoded size of a source-free claim value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 65536
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/claimValue/properties/nullable",
        "path_kind": "property"
      },
      "purpose": "States whether the source-free claim value may be null.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/claimValue/properties/type",
        "path_kind": "property"
      },
      "purpose": "Declares the boolean, integer, string, or date type of a source-free claim value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "boolean",
            "integer",
            "string",
            "date"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/consultations/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "integration",
            "input"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/consultations/additionalProperties/properties/input",
        "path_kind": "property"
      },
      "purpose": "Maps integration input names to reviewed target-request identifier or attribute bindings.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/consultations/additionalProperties/properties/input/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Closed target request binding. Attribute values are bounded typed caller-supplied context, not authenticated identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/targetRequestMapping",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "pattern",
          "value": "^request\\.target\\.(?:id|identifiers\\.[A-Za-z][A-Za-z0-9._-]{0,95}|attributes\\.[a-z][a-z0-9_]{0,63})$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/targetRequestMapping"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/consultations/additionalProperties/properties/input/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/consultations/additionalProperties/properties/integration",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/consultations/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/disclosure/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Maximum detail a claim may disclose.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/disclosureMode",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "value",
            "predicate",
            "redacted"
          ]
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/disclosureMode"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/disclosure/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "default",
            "allowed"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/disclosure/oneOf/1/properties/allowed",
        "path_kind": "property"
      },
      "purpose": "Lists the disclosure modes that may be selected in addition to the policy's declared default.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/disclosure/oneOf/1/properties/allowed/items",
        "path_kind": "array_item"
      },
      "purpose": "Maximum detail a claim may disclose.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/disclosureMode",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "value",
            "predicate",
            "redacted"
          ]
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/disclosureMode"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/disclosure/oneOf/1/properties/default",
        "path_kind": "property"
      },
      "purpose": "Maximum detail a claim may disclose.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/disclosureMode",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "value",
            "predicate",
            "redacted"
          ]
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/disclosureMode"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/access",
        "path_kind": "property"
      },
      "purpose": "Scopes a caller must hold to use an evidence service.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/access",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "scopes"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/access"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims",
        "path_kind": "property"
      },
      "purpose": "Maps evidence claim identifiers to an output or CEL expression, value contract, and disclosure policy.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": true
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "disclosure"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "output"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "cel"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties/properties/cel",
        "path_kind": "property"
      },
      "purpose": "Provides the CEL expression used for a source-free evaluation-only evidence claim.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties/properties/disclosure",
        "path_kind": "property"
      },
      "purpose": "Fixed disclosure mode or a default constrained by explicitly allowed alternatives.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/disclosure",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/disclosure"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties/properties/output",
        "path_kind": "property"
      },
      "purpose": "Selects the exact Relay consultation output that backs this evidence claim.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/additionalProperties/properties/value",
        "path_kind": "property"
      },
      "purpose": "Explicit claim value type, nullability, and encoded-size bound for source-free evaluation. A source-free claim cannot be selected by a credential profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/claimValue",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/claimValue"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/claims/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/consent",
        "path_kind": "property"
      },
      "purpose": "States whether evaluation of this evidence service requires consent.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "not_required",
            "required"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/consultations",
        "path_kind": "property"
      },
      "purpose": "Relay consultations and their closed bindings to target request identifiers or caller-supplied target attributes.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/consultations",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/consultations"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles",
        "path_kind": "property"
      },
      "purpose": "Credential profiles may select only claims backed by an exact Relay consultation. Source-free claim evaluation cannot be exposed as credential capability.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "format",
            "type",
            "validity",
            "claims"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/additionalProperties/properties/claims",
        "path_kind": "property"
      },
      "purpose": "Lists the registry-backed evidence claims selected into this credential profile.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/additionalProperties/properties/claims/items",
        "path_kind": "array_item"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/additionalProperties/properties/format",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/additionalProperties/properties/type",
        "path_kind": "property"
      },
      "purpose": "Declares the credential type identifier emitted for this reviewed credential profile.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/additionalProperties/properties/validity",
        "path_kind": "property"
      },
      "purpose": "Bounds the lifetime of credentials issued from this profile using a positive duration.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[1-9][0-9]*(?:s|m|h)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/credential_profiles/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/kind",
        "path_kind": "property"
      },
      "purpose": "Identifies this service declaration as a Notary evidence policy.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "evidence"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/legal_basis",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/purpose",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/subject_type",
        "path_kind": "property"
      },
      "purpose": "Subject category evaluated by this evidence service. Omission is normalized to person.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "person",
            "project"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/variables",
        "path_kind": "property"
      },
      "purpose": "Typed request variables exposed to evidence evaluation.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/variables",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/variables"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/evidenceService/properties/version",
        "path_kind": "property"
      },
      "purpose": "Assigns the positive authored version used to track this evidence-service policy contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/fieldList/items",
        "path_kind": "array_item"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/filterOperators/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "eq",
            "in",
            "gte",
            "lte",
            "between"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "measures"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "indicators"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/access",
        "path_kind": "property"
      },
      "purpose": "Defines optional metadata and aggregate scopes and whether execution is restricted to aggregate-only access.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAggregateAccess",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateAccess"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/allowed_filters",
        "path_kind": "property"
      },
      "purpose": "Maps aggregate filter fields to the comparison operators permitted for each field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/allowed_filters/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Allowed operators for one queryable field.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/filterOperators",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/filterOperators"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/default_group_by",
        "path_kind": "property"
      },
      "purpose": "Bounded unique list of entity field identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/fieldList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/fieldList"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/description",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/dimensions",
        "path_kind": "property"
      },
      "purpose": "Lists the labeled entity fields available as governed aggregate dimensions.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/dimensions/items",
        "path_kind": "array_item"
      },
      "purpose": "Named grouping dimension backed by one entity field.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAggregateDimension",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateDimension"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/disclosure_control",
        "path_kind": "property"
      },
      "purpose": "Defines the minimum group size and suppression behavior applied before aggregate results are disclosed.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/disclosure_control/properties/min_group_size",
        "path_kind": "property"
      },
      "purpose": "Sets the smallest result group that may be disclosed without suppression.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/disclosure_control/properties/suppression",
        "path_kind": "property"
      },
      "purpose": "Selects whether undersized aggregate groups are omitted, masked, or represented as null.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "omit",
            "mask",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/group_by",
        "path_kind": "property"
      },
      "purpose": "Bounded unique list of entity field identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/fieldList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/fieldList"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/indicators",
        "path_kind": "property"
      },
      "purpose": "Lists the named aggregate indicators, functions, source columns, and measurement metadata.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/indicators/items",
        "path_kind": "array_item"
      },
      "purpose": "SDMX-style aggregate indicator with units and display metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAggregateIndicator",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "function",
            "column",
            "unit_measure"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/joins",
        "path_kind": "property"
      },
      "purpose": "Bounded unique list of entity field identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/fieldList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/fieldList"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/measures",
        "path_kind": "property"
      },
      "purpose": "Lists the named aggregation functions and entity columns used to compute this aggregate.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/measures/items",
        "path_kind": "array_item"
      },
      "purpose": "Named aggregate calculation over one entity column.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAggregateMeasure",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "function",
            "column"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateMeasure"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/required_principal_filters",
        "path_kind": "property"
      },
      "purpose": "Bounded unique list of entity field identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/fieldList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/fieldList"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/spatial",
        "path_kind": "property"
      },
      "purpose": "Defines the reviewed administrative-area spatial aggregation and geometry materialization bindings.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAggregateSpatial",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "mode",
            "dimension",
            "geometry_entity",
            "geometry_id_field",
            "geometry_field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/temporal_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate/properties/title",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateAccess/properties/aggregate_only_execution",
        "path_kind": "property"
      },
      "purpose": "Restricts this definition to aggregate execution so it cannot be used as a record-level result path.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateAccess/properties/aggregate_scope",
        "path_kind": "property"
      },
      "purpose": "Authorization scope token.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateAccess/properties/metadata_scope",
        "path_kind": "property"
      },
      "purpose": "Authorization scope token.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateDimension/properties/codelist",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateDimension/properties/field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateDimension/properties/id",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateDimension/properties/label",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/column",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/decimals",
        "path_kind": "property"
      },
      "purpose": "Sets the non-negative decimal precision published for this aggregate indicator.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/definition_uri",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/frequency",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/function",
        "path_kind": "property"
      },
      "purpose": "Selects the aggregation function used to compute this named indicator.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/recordAggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateFunction"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/id",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/label",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/unit_measure",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateIndicator/properties/unit_mult",
        "path_kind": "property"
      },
      "purpose": "Declares the base-ten unit multiplier published with this aggregate indicator.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 2147483647
        },
        {
          "keyword": "minimum",
          "value": -2147483648
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateMeasure/properties/column",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateMeasure/properties/function",
        "path_kind": "property"
      },
      "purpose": "Selects the aggregation function applied to the optional source column for this measure.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/recordAggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateFunction"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateMeasure/properties/name",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/bbox_fields",
        "path_kind": "property"
      },
      "purpose": "Maps the geometry entity fields that provide the minimum and maximum coordinates of its bounding box.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordSpatialBbox",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "min_x",
            "min_y",
            "max_x",
            "max_y"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialBbox"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/collection_id",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/dimension",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/geometry_entity",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/geometry_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/geometry_id_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/max_geometry_vertices",
        "path_kind": "property"
      },
      "purpose": "Caps the number of vertices accepted when materializing one administrative-area geometry.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAggregateSpatial/properties/mode",
        "path_kind": "property"
      },
      "purpose": "Selects the supported administrative-area aggregation mode for this spatial definition.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "admin_area"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseExpression/properties/cel",
        "path_kind": "property"
      },
      "purpose": "Provides the bounded CEL expression evaluated only against the projected source object.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims",
        "path_kind": "property"
      },
      "purpose": "Maps released claim names to their reviewed source or expression, requiredness, and sensitivity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": true
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "required",
            "sensitivity"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "source_field"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "expression"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties/properties/expression",
        "path_kind": "property"
      },
      "purpose": "Bounded CEL evaluated only against the projected source object.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAttributeReleaseExpression",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "cel"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseExpression"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties/properties/required",
        "path_kind": "property"
      },
      "purpose": "States whether failure to produce this released claim makes the attribute-release result invalid.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties/properties/sensitivity",
        "path_kind": "property"
      },
      "purpose": "Classifies the released claim as a direct identifier, personal, public, or pseudonymous value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "direct_identifier",
            "personal",
            "public",
            "pseudonymous"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/additionalProperties/properties/source_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/claims/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/description",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/purpose",
        "path_kind": "property"
      },
      "purpose": "Binds the release to one permitted records purpose and requires a bounded visible-ASCII header token.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/release_conditions",
        "path_kind": "property"
      },
      "purpose": "Contains the bounded expression that must authorize this purpose-bound attribute release.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "expression"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/release_conditions/properties/expression",
        "path_kind": "property"
      },
      "purpose": "Bounded CEL evaluated only against the projected source object.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAttributeReleaseExpression",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "cel"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseExpression"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/release_scope",
        "path_kind": "property"
      },
      "purpose": "Requires the exact entity-bound <entity_id>:identity_release scope and keeps release access distinct from records API scopes.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/subject",
        "path_kind": "property"
      },
      "purpose": "Defines the projected source field and identifier type used for exact-one subject resolution.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "source_field",
            "id_type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/subject/properties/id_type",
        "path_kind": "property"
      },
      "purpose": "Labels the identifier type represented by the resolved subject identifier.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 64
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/subject/properties/source_field",
        "path_kind": "property"
      },
      "purpose": "Selects the projected entity field whose value is matched for exact-one subject resolution.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/title",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile/properties/version",
        "path_kind": "property"
      },
      "purpose": "Assigns a portable path-segment version matching [A-Za-z0-9][A-Za-z0-9._-]{0,63} to identify one attribute-release profile contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 64
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfiles/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "One purpose-bound, minimized identity release compiled into the owning Relay entity.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAttributeReleaseProfile",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "version",
            "purpose",
            "release_scope",
            "subject",
            "release_conditions",
            "claims"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfile"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfiles/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordFieldMap/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordFieldMap/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/bbox_fields",
        "path_kind": "property"
      },
      "purpose": "Maps optional entity fields containing precomputed minimum and maximum bounding-box coordinates.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordSpatialBbox",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "min_x",
            "min_y",
            "max_x",
            "max_y"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialBbox"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/collection_id",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/datetime_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/description",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/geometry",
        "path_kind": "property"
      },
      "purpose": "Defines whether feature geometry comes from point-coordinate fields or one encoded geometry field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordSpatialGeometry",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/max_bbox_degrees",
        "path_kind": "property"
      },
      "purpose": "Caps the geographic span accepted for one bounding-box query.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "number"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "exclusiveMinimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "number"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/max_geometry_vertices",
        "path_kind": "property"
      },
      "purpose": "Caps the number of vertices accepted when returning one feature geometry.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial/properties/title",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialBbox/properties/max_x",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialBbox/properties/max_y",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialBbox/properties/min_x",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialBbox/properties/min_y",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "kind",
            "longitude_field",
            "latitude_field",
            "crs"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/0/properties/crs",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/0/properties/kind",
        "path_kind": "property"
      },
      "purpose": "Selects geometry assembled from separate longitude and latitude entity fields.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "point"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/0/properties/latitude_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/0/properties/longitude_field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "kind",
            "field",
            "crs"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/1/properties/crs",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/1/properties/field",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpatialGeometry/oneOf/1/properties/kind",
        "path_kind": "property"
      },
      "purpose": "Selects the GeoJSON, WKT, or WKB encoding used by the configured geometry field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "geojson",
            "wkt",
            "wkb"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci/properties/expression_fields",
        "path_kind": "property"
      },
      "purpose": "Maps SP-DCI expression input names to the entity fields available during expression evaluation.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordFieldMap",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordFieldMap"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci/properties/identifiers",
        "path_kind": "property"
      },
      "purpose": "Maps SP-DCI identifier names to the entity fields used to identify a record.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordFieldMap",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordFieldMap"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci/properties/record_type",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci/properties/registry",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci/properties/registry_type",
        "path_kind": "property"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci/properties/response_fields",
        "path_kind": "property"
      },
      "purpose": "Maps SP-DCI response names to the entity fields returned for an authorized record.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordFieldMap",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordFieldMap"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/aggregates",
        "path_kind": "property"
      },
      "purpose": "Maps aggregate identifiers to governed aggregate definitions exposed by the records API.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/aggregates/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Governed aggregate definition with disclosure controls.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAggregate",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "description",
            "disclosure_control"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAggregate"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/aggregates/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/attribute_release_profiles",
        "path_kind": "property"
      },
      "purpose": "Purpose-bound, exact-one identity releases keyed by stable profile id. Generated Relay responses omit source metadata and are never cacheable.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordAttributeReleaseProfiles",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordAttributeReleaseProfiles"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/filters",
        "path_kind": "property"
      },
      "purpose": "Maps filterable entity fields to the comparison operators the records API permits for each field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 256
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/filters/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Allowed operators for one queryable field.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/filterOperators",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/filterOperators"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/filters/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/pagination",
        "path_kind": "property"
      },
      "purpose": "Defines the default and maximum row limits enforced by records API pagination.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "default_limit",
            "max_limit"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/pagination/properties/default_limit",
        "path_kind": "property"
      },
      "purpose": "Sets the row limit applied when a records request does not supply its own limit.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 10000
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/pagination/properties/max_limit",
        "path_kind": "property"
      },
      "purpose": "Caps the row limit that any records request may select; it must be at least 2 when attribute-release profiles are configured so ambiguous subjects can be detected.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 10000
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/projection",
        "path_kind": "property"
      },
      "purpose": "Lists the entity fields that the records API is permitted to project into row responses.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 256
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/projection/items",
        "path_kind": "array_item"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/purposes",
        "path_kind": "property"
      },
      "purpose": "Lists the bounded purpose identifiers accepted by this records API policy.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/purposes/items",
        "path_kind": "array_item"
      },
      "purpose": "Non-empty token without commas, whitespace, or control characters.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships",
        "path_kind": "property"
      },
      "purpose": "Declares the bounded named relationships that records queries may follow between authored entities.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "kind",
            "target",
            "foreign_key"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships/additionalProperties/properties/concept_uri",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships/additionalProperties/properties/foreign_key",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships/additionalProperties/properties/kind",
        "path_kind": "property"
      },
      "purpose": "Selects whether one declared records relationship belongs to, has many, or has one target record.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "belongs_to",
            "has_many",
            "has_one"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships/additionalProperties/properties/target",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/relationships/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/required_principal_filters",
        "path_kind": "property"
      },
      "purpose": "Lists principal-bound fields required for records queries; it must be empty when attribute-release profiles are configured because subject lookup cannot supply principal filters.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/fieldList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/fieldList"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/scopes",
        "path_kind": "property"
      },
      "purpose": "Groups the authorization scopes required for records metadata, row access, aggregates, and evidence verification.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "metadata",
            "rows"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/scopes/properties/aggregate",
        "path_kind": "property"
      },
      "purpose": "Authorization scope token.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/scopes/properties/evidence_verification",
        "path_kind": "property"
      },
      "purpose": "Authorization scope token.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/scopes/properties/metadata",
        "path_kind": "property"
      },
      "purpose": "Authorization scope token.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/scopes/properties/rows",
        "path_kind": "property"
      },
      "purpose": "Authorization scope token.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/scope",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/scope"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards",
        "path_kind": "property"
      },
      "purpose": "Declares whether this records API exposes its reviewed OGC Features and SP-DCI standards profiles.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "ogc_features",
            "sp_dci"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards/properties/ogc_features",
        "path_kind": "property"
      },
      "purpose": "Disables OGC API Features support or supplies the reviewed spatial profile used to enable it.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": true
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards/properties/ogc_features/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": false
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards/properties/ogc_features/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "OGC API Features collection metadata and bounded geometry mapping.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordSpatial",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "geometry"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordSpatial"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards/properties/sp_dci",
        "path_kind": "property"
      },
      "purpose": "Disables SP-DCI support or supplies the reviewed registry mapping used to enable it.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": true
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards/properties/sp_dci/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": false
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsApi/properties/standards/properties/sp_dci/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "SP-DCI registry identity and field mappings for a records service.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordSpdci",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "registry",
            "registry_type",
            "record_type",
            "identifiers",
            "expression_fields"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordSpdci"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/access_rights",
        "path_kind": "property"
      },
      "purpose": "Classifies the records service as public, restricted, or non-public for catalog and access metadata.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "public",
            "restricted",
            "non_public"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/api",
        "path_kind": "property"
      },
      "purpose": "Relay records API behavior, authorization, query bounds, and standards profiles.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordsApi",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "scopes",
            "projection",
            "pagination",
            "standards"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordsApi"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/conforms_to",
        "path_kind": "property"
      },
      "purpose": "Lists the standards or specifications to which the records service declares conformance.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/conforms_to/items",
        "path_kind": "array_item"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/description",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/entity",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/kind",
        "path_kind": "property"
      },
      "purpose": "Identifies this service declaration as a Relay records API backed by an authored entity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "records_api"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/owner",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/sensitivity",
        "path_kind": "property"
      },
      "purpose": "Classifies the overall sensitivity of records exposed by this service declaration.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "public",
            "internal",
            "personal",
            "confidential",
            "secret"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/title",
        "path_kind": "property"
      },
      "purpose": "Bounded human-readable project metadata.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/text",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/text"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/recordsService/properties/update_frequency",
        "path_kind": "property"
      },
      "purpose": "Declares the reviewed cadence at which the records service's backing data is updated.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "continuous",
            "daily",
            "weekly",
            "termly",
            "monthly",
            "quarterly",
            "annual",
            "irregular",
            "as_needed",
            "unknown"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/service/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Notary evidence policy, consultations, claims, and registry-backed credential profiles. Source-free claims remain evaluation-only and cannot be selected by a credential profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/evidenceService",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "kind",
            "version",
            "purpose",
            "legal_basis",
            "consent",
            "access",
            "claims"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/evidenceService"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/service/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Relay records API backed by one authored materialized entity.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/recordsService",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "kind",
            "entity",
            "api"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/recordsService"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/variables/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "from",
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/variables/additionalProperties/properties/from",
        "path_kind": "property"
      },
      "purpose": "Binds one evidence variable to its caller-supplied request variable path.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^request\\.variables\\.[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/variables/additionalProperties/properties/type",
        "path_kind": "property"
      },
      "purpose": "Declares the request variable as a date value for typed evidence evaluation.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "date"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/$defs/variables/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "integrations"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/anyOf/0/properties/integrations",
        "path_kind": "property"
      },
      "purpose": "Requires at least one authored integration when the project satisfies the integration-content alternative.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "entities"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/anyOf/1/properties/entities",
        "path_kind": "property"
      },
      "purpose": "Requires at least one authored entity when the project satisfies the entity-content alternative.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/anyOf/2",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "services"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/anyOf/2/properties/services",
        "path_kind": "property"
      },
      "purpose": "Requires at least one authored service when the project satisfies the service-content alternative.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/entities",
        "path_kind": "property"
      },
      "purpose": "Materialized entity definitions keyed by project-local entity identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/entities/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/entities/additionalProperties/properties/file",
        "path_kind": "property"
      },
      "purpose": "Selects the project-relative authored entity document for this project-local entity identifier.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/relativePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!/)(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/relativePath"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/entities/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/integrations",
        "path_kind": "property"
      },
      "purpose": "Source adaptation definitions keyed by project-local integration identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/integrations/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/integrations/additionalProperties/properties/file",
        "path_kind": "property"
      },
      "purpose": "Selects the project-relative authored integration document for this project-local integration identifier.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/relativePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!/)(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/relativePath"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/integrations/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/registry",
        "path_kind": "property"
      },
      "purpose": "Stable identity of the Registry Stack project.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/registry/properties/id",
        "path_kind": "property"
      },
      "purpose": "Assigns the stable project-local registry identifier used to bind generated product inputs and review artifacts.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/services",
        "path_kind": "property"
      },
      "purpose": "Relay records APIs and Notary evidence services exposed by the project.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/services/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Closed choice between a Notary evidence service and a Relay records service.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/service",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/service"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/services/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/starter",
        "path_kind": "property"
      },
      "purpose": "Immutable provenance for a workspace initialized from a Registry Stack starter. The digest excludes this content_digest field and covers the starter's authored project files.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "release",
            "content_digest"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/starter/properties/content_digest",
        "path_kind": "property"
      },
      "purpose": "Digest of the initialized starter authoring content, used to report later workspace divergence.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/starter/properties/id",
        "path_kind": "property"
      },
      "purpose": "Registry Stack starter identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/starter/properties/release",
        "path_kind": "property"
      },
      "purpose": "Registry Stack release that supplied the starter.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[^,\\s\\u0000-\\u001F\\u007F]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "project",
        "pointer": "/$defs/token"
      }
    },
    {
      "address": {
        "schema": "project",
        "pointer": "/properties/version",
        "path_kind": "property"
      },
      "purpose": "Project authoring format version.",
      "purpose_source": "schema_description",
      "semantic_owner": "authoring_contract",
      "human_owner": "registry_maintainers",
      "scope": "The product-neutral project graph and the Relay or Notary services that consume its authored contracts.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "public",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.project.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and values from a maintained golden workspace; never copy a private country contract into reference data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Revalidate and rebuild the project after changing this field; coordinate a deployment when generated product inputs change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "",
        "path_kind": "root"
      },
      "purpose": "Binds a Registry Stack project to environment-specific services, sources, credentials, and deployment topology.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": true
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "version",
            "deployment"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/ca/properties/file",
        "path_kind": "property"
      },
      "purpose": "Normalized absolute path without dot segments or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/ca/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the operator-controlled trust-root generation used for explicit certificate-authority rotation.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "username",
            "password",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/0/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the generation of the operator-managed basic-authentication credential references.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/0/properties/password",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/0/properties/username",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "token",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/1/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the generation of the operator-managed bearer-token credential reference.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/1/properties/token",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/2",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "client_id",
            "client_secret",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/2/properties/client_id",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/2/properties/client_secret",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/2/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the generation of the operator-managed OAuth client credential references.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/3",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "value",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/3/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the generation of the operator-managed API-key credential reference.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/credential/oneOf/3/properties/value",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/endpoint/properties/allowed_private_cidrs",
        "path_kind": "property"
      },
      "purpose": "Explicit private network ranges this source may resolve to.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/privateCidrs",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/privateCidrs"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/endpoint/properties/ca",
        "path_kind": "property"
      },
      "purpose": "Pinned certificate-authority file and its rotation generation.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ca",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/ca"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/endpoint/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the operator-controlled private-endpoint generation used for explicit binding rotation.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/endpoint/properties/mtls",
        "path_kind": "property"
      },
      "purpose": "Client certificate and private-key reference for mutual TLS.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/mtls",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "certificate_file",
            "private_key",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/mtls"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/endpoint/properties/origin",
        "path_kind": "property"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/endpoint/properties/path",
        "path_kind": "property"
      },
      "purpose": "Binds a reviewed private endpoint path beneath its separately configured origin.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//)(?!.*[?#]).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/entity/properties/columns",
        "path_kind": "property"
      },
      "purpose": "Maps authored entity field names to columns supplied by the environment-owned provider.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/entity/properties/columns/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/entity/properties/columns/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/entity/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the operator-controlled generation of this entity materialization binding.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/entity/properties/provider",
        "path_kind": "property"
      },
      "purpose": "Environment-specific physical provider for a materialized entity.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/provider",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/provider"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/entity/properties/source_revision",
        "path_kind": "property"
      },
      "purpose": "Records the operator-supplied revision label of the bound entity source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/integration/properties/source",
        "path_kind": "property"
      },
      "purpose": "Runtime source connection policy for one authored integration.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/source",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "origin"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/source"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/internalOrigin/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/internalOrigin/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "HTTP IP-loopback origin; public Relay and issuer fields restrict it to the local profile, while internal Notary-to-Relay connections allow it in any profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/localLoopbackOrigin",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP]://(?:127(?:\\.[0-9]{1,3}){3}|\\[::1\\])(?::[0-9]+)?/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/localLoopbackOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/mtls/properties/certificate_file",
        "path_kind": "property"
      },
      "purpose": "Normalized absolute path without dot segments or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/mtls/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the operator-controlled mutual-TLS generation used for explicit certificate and key rotation.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/mtls/properties/private_key",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/access_token",
        "path_kind": "property"
      },
      "purpose": "Dedicated Notary access-token signing key and published key identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "signing_key",
            "signing_kid"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/access_token/properties/signing_key",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/access_token/properties/signing_kid",
        "path_kind": "property"
      },
      "purpose": "Bounded visible-ASCII token, including full verification-method identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token2048",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token2048"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/allowed_wallet_origins",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS browser origins admitted to the wallet-facing Notary routes.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/allowed_wallet_origins/items",
        "path_kind": "array_item"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/authorization_server",
        "path_kind": "property"
      },
      "purpose": "Pinned eSignet issuer and exact endpoints used for login and token validation.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "issuer",
            "jwks_url",
            "userinfo_url",
            "authorize_url",
            "token_url"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/authorization_server/properties/authorize_url",
        "path_kind": "property"
      },
      "purpose": "Relay authentication resource using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayResource",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/authorization_server/properties/issuer",
        "path_kind": "property"
      },
      "purpose": "Relay or issuer origin using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayOrigin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/authorization_server/properties/jwks_url",
        "path_kind": "property"
      },
      "purpose": "Relay authentication resource using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayResource",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/authorization_server/properties/token_url",
        "path_kind": "property"
      },
      "purpose": "Relay authentication resource using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayResource",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/authorization_server/properties/userinfo_url",
        "path_kind": "property"
      },
      "purpose": "Relay authentication resource using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayResource",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/client",
        "path_kind": "property"
      },
      "purpose": "eSignet relying-party identity and dedicated private-key reference.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "signing_key",
            "signing_kid"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/client/properties/id",
        "path_kind": "property"
      },
      "purpose": "Bounded visible-ASCII protocol token.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token256",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token256"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/client/properties/signing_key",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/client/properties/signing_kid",
        "path_kind": "property"
      },
      "purpose": "Bounded visible-ASCII token, including full verification-method identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token2048",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token2048"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/credential",
        "path_kind": "property"
      },
      "purpose": "Existing project service and credential profile exposed through OID4VCI.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "service",
            "profile"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/credential/properties/profile",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/credential/properties/service",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/public_base_url",
        "path_kind": "property"
      },
      "purpose": "Relay or issuer origin using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayOrigin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/redirect_uri",
        "path_kind": "property"
      },
      "purpose": "Relay authentication resource using HTTPS, or HTTP IP-loopback under the local profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayResource",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/sensitive_state_key",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/subject",
        "path_kind": "property"
      },
      "purpose": "Verified eSignet userinfo claim bound exactly to the credential subject identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "token_claim",
            "id_type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/subject/properties/id_type",
        "path_kind": "property"
      },
      "purpose": "Bounded visible-ASCII protocol token.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token256",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token256"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/subject/properties/token_claim",
        "path_kind": "property"
      },
      "purpose": "Bounded visible-ASCII protocol token.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token256",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token256"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/tx_code",
        "path_kind": "property"
      },
      "purpose": "Transaction-code policy. Omit for the secure required-PIN default. Set required=false only for a bounded bearer-offer interoperability profile; the compiler fixes the offer lifetime at 300 seconds.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci/properties/tx_code/properties/required",
        "path_kind": "property"
      },
      "purpose": "States whether OID4VCI authorization requires a transaction code before credential issuance.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "schema_value": true
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/privateCidrs/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 64
        },
        {
          "keyword": "minLength",
          "value": 3
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/0/properties/delimiter",
        "path_kind": "property"
      },
      "purpose": "Selects the byte used to delimit fields in the bound CSV source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 255
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/0/properties/header_row",
        "path_kind": "property"
      },
      "purpose": "Selects the one-based CSV row containing source column headers.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/0/properties/path",
        "path_kind": "property"
      },
      "purpose": "Normalized absolute path without dot segments or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/0/properties/quote",
        "path_kind": "property"
      },
      "purpose": "Selects the byte used to quote fields in the bound CSV source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 255
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/0/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects CSV as the environment-owned materialization provider for an authored entity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "csv"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "project_file",
            "path",
            "sheet"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1/properties/data_range",
        "path_kind": "property"
      },
      "purpose": "Restricts entity materialization to the reviewed range within the selected worksheet.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1/properties/header_row",
        "path_kind": "property"
      },
      "purpose": "Selects the one-based XLSX row containing source column headers.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1/properties/path",
        "path_kind": "property"
      },
      "purpose": "Normalized absolute path without dot segments or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1/properties/project_file",
        "path_kind": "property"
      },
      "purpose": "Binds a contained project-relative workbook for offline preflight and read-only runtime mounting without emitting the authoring path into Relay configuration.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/relativePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!/)(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relativePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1/properties/sheet",
        "path_kind": "property"
      },
      "purpose": "Names the worksheet read from the environment-owned XLSX source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/1/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects XLSX as the environment-owned materialization provider for an authored entity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "xlsx"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/2",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/2/properties/path",
        "path_kind": "property"
      },
      "purpose": "Normalized absolute path without dot segments or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/2/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects Parquet as the environment-owned materialization provider for an authored entity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "parquet"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/3",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "connection",
            "schema",
            "table"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/3/properties/connection",
        "path_kind": "property"
      },
      "purpose": "Reference to a process-environment variable; secret values are never authored here.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/3/properties/schema",
        "path_kind": "property"
      },
      "purpose": "Portable unquoted PostgreSQL schema or table identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/postgresIdentifier",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,62}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/postgresIdentifier"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/3/properties/table",
        "path_kind": "property"
      },
      "purpose": "Portable unquoted PostgreSQL schema or table identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/postgresIdentifier",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,62}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/postgresIdentifier"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/provider/oneOf/3/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects PostgreSQL as the environment-owned materialization provider for an authored entity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "postgres"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/relayOrigin/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/relayOrigin/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "HTTP IP-loopback origin; public Relay and issuer fields restrict it to the local profile, while internal Notary-to-Relay connections allow it in any profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/localLoopbackOrigin",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP]://(?:127(?:\\.[0-9]{1,3}){3}|\\[::1\\])(?::[0-9]+)?/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/localLoopbackOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/relayResource/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/relayResource/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "HTTP IP-loopback resource accepted only with the local deployment profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/localLoopbackResource",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP]://(?:127(?:\\.[0-9]{1,3}){3}|\\[::1\\])(?::[0-9]+)?/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/localLoopbackResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/secret/properties/secret",
        "path_kind": "property"
      },
      "purpose": "Names the operator-managed environment secret reference without containing the secret value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Z_][A-Z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/service/properties/service",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/allowed_private_cidrs",
        "path_kind": "property"
      },
      "purpose": "Explicit private network ranges this source may resolve to.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/privateCidrs",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/privateCidrs"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/ca",
        "path_kind": "property"
      },
      "purpose": "Pinned certificate-authority file and its rotation generation.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ca",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/ca"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/concurrency",
        "path_kind": "property"
      },
      "purpose": "Caps the number of requests that may be in flight concurrently for this source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 64
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/credential",
        "path_kind": "property"
      },
      "purpose": "One supported source credential shape, containing references rather than values.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/credential",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/credential"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/jwks",
        "path_kind": "property"
      },
      "purpose": "Security-bound HTTPS endpoint with optional private-network, CA, and mTLS policy.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/endpoint",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "origin",
            "path",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/endpoint"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/mtls",
        "path_kind": "property"
      },
      "purpose": "Client certificate and private-key reference for mutual TLS.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/mtls",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "certificate_file",
            "private_key",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/mtls"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/oauth",
        "path_kind": "property"
      },
      "purpose": "Security-bound HTTPS endpoint with optional private-network, CA, and mTLS policy.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/endpoint",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "origin",
            "path",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/endpoint"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/origin",
        "path_kind": "property"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/rate",
        "path_kind": "property"
      },
      "purpose": "Defines the per-minute request rate and burst bounds applied to one environment source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "per_minute",
            "burst"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/rate/properties/burst",
        "path_kind": "property"
      },
      "purpose": "Caps the short request burst permitted by the source rate limiter.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 1024
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/rate/properties/per_minute",
        "path_kind": "property"
      },
      "purpose": "Caps the number of requests permitted to this source during one minute.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 60000
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/$defs/source/properties/timeout",
        "path_kind": "property"
      },
      "purpose": "Optionally narrows one environment source request to a positive timeout no greater than twenty seconds.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,3}|1[0-9]{4}|20000)ms|(?:[1-9]|1[0-9]|20)s)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/0/else",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/0/else/not",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/0/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "deployment"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/0/if/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Matches environments whose deployment declaration enables Relay so the corresponding Relay binding is required.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/0/then",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/1/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary_relay"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/1/then",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/1/then/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Requires both Relay and Notary deployment services when a Notary-to-Relay binding is present.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay",
            "notary"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/2",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/2/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay_state"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/2/then",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/2/then/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Requires the Relay deployment service when Relay state storage is configured.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/3",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/3/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary_state"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/3/then",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/3/then/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Requires the Notary deployment service when Notary state storage is configured.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/4",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/4/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary_cel"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/4/then",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/4/then/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Requires the Notary deployment service when a Notary CEL worker memory bound is configured.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/5",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/5/else",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/5/else/properties/callers",
        "path_kind": "property"
      },
      "purpose": "When callers are authored without OID4VCI, requires the caller map to contain at least one binding; cross-file validation separately requires callers for Notary environments and rejects them for Relay-only topology.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/5/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "oid4vci"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/5/then",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary_state"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/5/then/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Requires the Notary deployment service when OID4VCI issuance is configured.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci",
        "path_kind": "property"
      },
      "purpose": "Applies non-local HTTPS constraints to public OID4VCI endpoints.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/authorization_server",
        "path_kind": "property"
      },
      "purpose": "Applies non-local HTTPS constraints to all configured OID4VCI authorization-server endpoints.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/authorization_server/properties/authorize_url",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/authorization_server/properties/issuer",
        "path_kind": "property"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/authorization_server/properties/jwks_url",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/authorization_server/properties/token_url",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/authorization_server/properties/userinfo_url",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/public_base_url",
        "path_kind": "property"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/oid4vci/properties/redirect_uri",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/relay",
        "path_kind": "property"
      },
      "purpose": "Applies non-local HTTPS constraints to the Relay origin, issuer, and key-set bindings.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/relay/not",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "local_api_keys"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/relay/properties/issuer",
        "path_kind": "property"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/relay/properties/jwks_url",
        "path_kind": "property"
      },
      "purpose": "Exact HTTPS resource without query or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/httpsResource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/[^?#]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/httpsResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/else/properties/relay/properties/origin",
        "path_kind": "property"
      },
      "purpose": "HTTPS origin without path, query, or fragment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/origin",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uri"
        },
        {
          "keyword": "pattern",
          "value": "^[hH][tT][tT][pP][sS]://[^/?#]+/?$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/origin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/if",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/if/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Matches the local deployment profile before relaxing public endpoint transport constraints.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "profile"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/allOf/6/if/properties/deployment/properties/profile",
        "path_kind": "property"
      },
      "purpose": "Selects the local-profile condition used by the environment transport-validation branch.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "local"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/callers",
        "path_kind": "property"
      },
      "purpose": "Notary API-key caller identities and the scopes each identity receives.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/callers/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "api_key_fingerprint",
            "scopes"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/callers/additionalProperties/properties/api_key_fingerprint",
        "path_kind": "property"
      },
      "purpose": "Names the secret reference used to verify one caller API key; neither the key nor fingerprint value is authored here.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/callers/additionalProperties/properties/scopes",
        "path_kind": "property"
      },
      "purpose": "Narrows one caller to the explicitly reviewed service scopes available in this environment.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/callers/additionalProperties/properties/scopes/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/callers/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/deployment",
        "path_kind": "property"
      },
      "purpose": "Products deployed in this environment and the operational profile they use.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": true
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "profile"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/deployment/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relay"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/deployment/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "notary"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/deployment/properties/notary",
        "path_kind": "property"
      },
      "purpose": "Binds an authored product role to a deployed service identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/service",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "service"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/service"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/deployment/properties/profile",
        "path_kind": "property"
      },
      "purpose": "Selects the deployment assurance profile whose service and transport conditions the environment must satisfy.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "local",
            "hosted_lab",
            "production",
            "evidence_grade"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/deployment/properties/relay",
        "path_kind": "property"
      },
      "purpose": "Binds an authored product role to a deployed service identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/service",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "service"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/service"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/entities",
        "path_kind": "property"
      },
      "purpose": "Environment-specific source bindings keyed by entity identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/entities/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Maps an authored entity to provider columns and immutable source-generation identifiers.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/entity",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "provider",
            "columns",
            "source_revision",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/entity"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/entities/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/integrations",
        "path_kind": "property"
      },
      "purpose": "Environment bindings keyed by authored integration identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/integrations/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Environment binding for an authored source integration.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/integration",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "source"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/integration"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/integrations/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/issuance",
        "path_kind": "property"
      },
      "purpose": "Notary issuer and signing-key bindings for credential issuance.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "issuer",
            "signing_key",
            "signing_kid",
            "generation"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/issuance/properties/algorithm",
        "path_kind": "property"
      },
      "purpose": "Credential issuer signing algorithm. Holder proof remains EdDSA with did:jwk.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "schema_value": "EdDSA"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "EdDSA",
            "ES256"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/issuance/properties/generation",
        "path_kind": "property"
      },
      "purpose": "Records the operator-controlled issuance-key generation used for explicit rotation and rollback checks.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/issuance/properties/issuer",
        "path_kind": "property"
      },
      "purpose": "Binds the operator-approved credential issuer identifier without granting claim or disclosure authority.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/issuance/properties/signing_key",
        "path_kind": "property"
      },
      "purpose": "Names the operator-managed secret reference for credential signing; the signing key value is never authored or reported.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/secret",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/secret"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/issuance/properties/signing_kid",
        "path_kind": "property"
      },
      "purpose": "Selects the reviewed signing-key identifier exposed in issued credential metadata without containing private key material.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token2048",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token2048"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_cel",
        "path_kind": "property"
      },
      "purpose": "Optional per-worker data/address-space ceiling for dedicated Notary CEL processes. The Notary default is 134217728 bytes; 1073741824 is the maximum emulation-compatible exception and remains a limit, not an allocation.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "worker_memory_bytes"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_cel/properties/worker_memory_bytes",
        "path_kind": "property"
      },
      "purpose": "Caps the memory available to one isolated Notary CEL worker.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 1073741824
        },
        {
          "keyword": "minimum",
          "value": 33554432
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_relay",
        "path_kind": "property"
      },
      "purpose": "Deployment-internal Relay connection, Notary workload identity, and token file used only when Notary consults Relay.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "base_url",
            "workload_client_id",
            "token_file"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_relay/properties/base_url",
        "path_kind": "property"
      },
      "purpose": "Binds Notary to the operator-reviewed Relay origin used for governed evidence consultations.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/internalOrigin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/internalOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_relay/properties/token_file",
        "path_kind": "property"
      },
      "purpose": "Selects the operator-managed token-file binding for Notary-to-Relay authentication without exposing its contents.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_relay/properties/workload_client_id",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary workload client authorized to request reviewed Relay consultations.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_state",
        "path_kind": "property"
      },
      "purpose": "Optional deployment binding for Notary-owned PostgreSQL state transport trust.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "postgresql"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_state/properties/postgresql",
        "path_kind": "property"
      },
      "purpose": "Selects the PostgreSQL trust binding used by Notary state storage.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "root_certificate_path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/notary_state/properties/postgresql/properties/root_certificate_path",
        "path_kind": "property"
      },
      "purpose": "Binds Notary state storage to an operator-managed PostgreSQL trust root at a deployment-local path.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/oid4vci",
        "path_kind": "property"
      },
      "purpose": "Explicit registry-backed holder-wallet OID4VCI binding for one authored Notary credential profile.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/oid4vci",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "public_base_url",
            "credential",
            "authorization_server",
            "client",
            "access_token",
            "sensitive_state_key",
            "subject",
            "redirect_uri",
            "allowed_wallet_origins"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/oid4vci"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay",
        "path_kind": "property"
      },
      "purpose": "Public Relay identity and token-validation settings for a Relay deployment.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "origin",
            "issuer",
            "jwks_url",
            "audience",
            "allowed_clients"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/allowed_clients",
        "path_kind": "property"
      },
      "purpose": "Narrows Relay authentication to the operator-reviewed client identifiers listed for this environment.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/allowed_clients/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/audience",
        "path_kind": "property"
      },
      "purpose": "Binds the token audience Relay requires so tokens issued for another service are rejected.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/issuer",
        "path_kind": "property"
      },
      "purpose": "Binds the expected token issuer for Relay authentication in this deployment environment.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayOrigin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/jwks_url",
        "path_kind": "property"
      },
      "purpose": "Binds the operator-reviewed key-set endpoint Relay uses to verify caller tokens.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayResource",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayResource"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/local_api_keys",
        "path_kind": "property"
      },
      "purpose": "Declares synthetic API-key principals only for the local profile; Registryctl generates raw keys privately and emits only their fingerprints to Relay.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "match_principal",
            "no_match_principal",
            "scopes"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/local_api_keys/properties/match_principal",
        "path_kind": "property"
      },
      "purpose": "Binds the synthetic local caller whose reviewed identifier matches one starter row; this identifier is not a raw key or a source value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token256",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token256"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/local_api_keys/properties/no_match_principal",
        "path_kind": "property"
      },
      "purpose": "Binds the synthetic local caller whose reviewed identifier intentionally matches no starter row so an empty result is maintained.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/token256",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^[!-~]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/token256"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/local_api_keys/properties/scopes",
        "path_kind": "property"
      },
      "purpose": "Limits both generated local API-key callers to the explicitly reviewed service scopes needed by the maintained checks.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/local_api_keys/properties/scopes/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay/properties/origin",
        "path_kind": "property"
      },
      "purpose": "Binds the externally visible Relay origin reviewed by the operator and local network policy.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "local_reference": "#/$defs/relayOrigin",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/relayOrigin"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay_state",
        "path_kind": "property"
      },
      "purpose": "Optional deployment binding for Relay-owned consultation PostgreSQL state transport trust.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "postgresql"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay_state/properties/postgresql",
        "path_kind": "property"
      },
      "purpose": "Selects the PostgreSQL trust binding used by Relay state storage.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "root_certificate_path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/relay_state/properties/postgresql/properties/root_certificate_path",
        "path_kind": "property"
      },
      "purpose": "Binds Relay state storage to an operator-managed PostgreSQL trust root at a deployment-local path.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/absolutePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 2
        },
        {
          "keyword": "pattern",
          "value": "^/(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "environment",
        "pointer": "/$defs/absolutePath"
      }
    },
    {
      "address": {
        "schema": "environment",
        "pointer": "/properties/version",
        "path_kind": "property"
      },
      "purpose": "Environment authoring format version.",
      "purpose_source": "schema_description",
      "semantic_owner": "deployment_security",
      "human_owner": "security_maintainers",
      "scope": "Operator-owned deployment, trust, secret-reference, network, caller, state, and product availability bindings.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "public",
      "state": "environment_bound",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "operator_preflight",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.environment.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use non-routable example origins and opaque example secret-reference names, never working credentials or private infrastructure details.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate deployment and secret or trust rotation with the environment operator before activating a changed binding.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "",
        "path_kind": "root"
      },
      "purpose": "Defines a product-neutral source adaptation contract using bounded HTTP, Rhai script, or exact snapshot capabilities.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "version",
            "id",
            "revision",
            "input",
            "capability",
            "outputs"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/allowRule/properties/method",
        "path_kind": "property"
      },
      "purpose": "Selects the GET or POST method permitted by one reviewed source allow rule.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "GET",
            "POST"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/allowRule/properties/path",
        "path_kind": "property"
      },
      "purpose": "Defines one reviewed source path template; concrete private endpoints and identifiers remain environment-owned.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^/[^?#]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/allowRule/properties/semantics",
        "path_kind": "property"
      },
      "purpose": "Declares that the permitted source operation has read-only semantics.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "read_only"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "http"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/0/properties/http",
        "path_kind": "property"
      },
      "purpose": "Selects the single-request declarative HTTP capability and its expected response semantics.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "request"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/0/properties/http/properties/request",
        "path_kind": "property"
      },
      "purpose": "Bounded read-only HTTP request template.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/httpRequest",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "method",
            "path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/0/properties/http/properties/response",
        "path_kind": "property"
      },
      "purpose": "Rules for translating upstream status and body cardinality into normalized outcomes.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/httpResponse",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "script"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/1/properties/script",
        "path_kind": "property"
      },
      "purpose": "Selects the reviewed project-relative script capability and its optional modules.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/1/properties/script/properties/file",
        "path_kind": "property"
      },
      "purpose": "Project-relative path without traversal or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/relativePath",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!/)(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/relativePath"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/1/properties/script/properties/modules",
        "path_kind": "property"
      },
      "purpose": "Lists the reviewed project-relative modules available to the integration script.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/1/properties/script/properties/modules/items",
        "path_kind": "array_item"
      },
      "purpose": "Project-relative path without traversal or duplicate separators.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/relativePath",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!/)(?!.*(?:^|/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/relativePath"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/2",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "snapshot"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/2/properties/snapshot",
        "path_kind": "property"
      },
      "purpose": "Selects an offline entity snapshot capability with exact input matching and freshness control.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "entity",
            "exact",
            "freshness"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/2/properties/snapshot/properties/entity",
        "path_kind": "property"
      },
      "purpose": "Lowercase stable identifier used in project references.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/2/properties/snapshot/properties/exact",
        "path_kind": "property"
      },
      "purpose": "Maps entity fields to integration inputs that must match exactly in the snapshot lookup.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 8
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/2/properties/snapshot/properties/exact/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Reference to a declared integration input.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/inputReference",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "input"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputReference"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/capability/oneOf/2/properties/snapshot/properties/freshness",
        "path_kind": "property"
      },
      "purpose": "Sets the maximum accepted age of the materialized entity snapshot within the product-owned 31-day ceiling.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,8}|1[0-9]{9}|2[0-5][0-9]{8}|26[0-6][0-9]{7}|267[0-7][0-9]{6}|2678[0-3][0-9]{5}|2678400000)ms|(?:[1-9][0-9]{0,5}|1[0-9]{6}|2[0-5][0-9]{5}|26[0-6][0-9]{4}|267[0-7][0-9]{3}|2678[0-3][0-9]{2}|2678400)s|(?:[1-9][0-9]{0,3}|[1-3][0-9]{4}|4[0-3][0-9]{3}|44[0-5][0-9]{2}|446[0-3][0-9]{1}|44640)m|(?:[1-9][0-9]{0,1}|[1-6][0-9]{2}|7[0-3][0-9]{1}|74[0-3]|744)h|(?:[1-9][0-9]{0,0}|[1-2][0-9]{1}|30|31)d)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/0/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects an unauthenticated, basic-authentication, or static-bearer credential interface.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "none",
            "basic",
            "static_bearer"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "name",
            "max_value_bytes"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/1/properties/max_value_bytes",
        "path_kind": "property"
      },
      "purpose": "Caps the credential value size accepted by the fixed-header API-key interface.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4096
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/1/properties/name",
        "path_kind": "property"
      },
      "purpose": "Declares the fixed HTTP header name used by the API-key credential interface.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z][A-Za-z0-9_-]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/1/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects the fixed-header API-key credential interface for this source contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "api_key_header"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/2",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "name",
            "max_value_bytes"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/2/properties/max_value_bytes",
        "path_kind": "property"
      },
      "purpose": "Caps the credential value size accepted by the fixed-query API-key interface.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4096
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/2/properties/name",
        "path_kind": "property"
      },
      "purpose": "Declares the fixed query parameter name used by the API-key credential interface.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9._:~-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/2/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects the fixed-query-parameter API-key credential interface for this source contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "api_key_query"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "request",
            "response_profile"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3/properties/audience",
        "path_kind": "property"
      },
      "purpose": "Constrains OAuth token acquisition to the reviewed source audience and is treated as sensitive operational metadata.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 2048
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3/properties/refresh_skew",
        "path_kind": "property"
      },
      "purpose": "Sets a positive refresh interval below sixty seconds so a cached OAuth credential retains usable lifetime.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,3}|[1-5][0-9]{4})ms|(?:[1-9]|[1-5][0-9])s)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3/properties/request",
        "path_kind": "property"
      },
      "purpose": "Selects form-encoded or JSON token requests for the OAuth client-credentials interface.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "form",
            "json"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3/properties/response_profile",
        "path_kind": "property"
      },
      "purpose": "Requires the bounded OAuth bearer-token response profile supported by the source adapter.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "oauth2_bearer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3/properties/scope",
        "path_kind": "property"
      },
      "purpose": "Declares the bounded OAuth scope string requested for this source credential.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 1024
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/credential/oneOf/3/properties/type",
        "path_kind": "property"
      },
      "purpose": "Selects the OAuth 2.0 client-credentials interface for source authentication.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "oauth2_client_credentials"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/body",
        "path_kind": "property"
      },
      "purpose": "Defines the optional authored body template sent by the declarative HTTP request.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/headers",
        "path_kind": "property"
      },
      "purpose": "Maps reviewed request header names to authored values and input substitutions.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/headers/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Request value supplied from a declared input or an authored scalar literal.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "string"
        ],
        "local_reference": "#/$defs/inputOrLiteral",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputOrLiteral"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/method",
        "path_kind": "property"
      },
      "purpose": "Selects the single GET or POST request performed by a declarative HTTP capability.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "GET",
            "POST"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/path",
        "path_kind": "property"
      },
      "purpose": "Defines the reviewed source path template used by the declarative HTTP request.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^/[^?#]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/query",
        "path_kind": "property"
      },
      "purpose": "Maps reviewed query parameter names to authored request values and input substitutions.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/query/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Request value supplied from a declared input or an authored scalar literal.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "string"
        ],
        "local_reference": "#/$defs/inputOrLiteral",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputOrLiteral"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpRequest/properties/semantics",
        "path_kind": "property"
      },
      "purpose": "Declares that the declarative HTTP request has read-only source semantics.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "read_only"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/ambiguous",
        "path_kind": "property"
      },
      "purpose": "Lists HTTP response statuses that produce the integration's ambiguous outcome.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/ambiguous/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 599
        },
        {
          "keyword": "minimum",
          "value": 100
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/no_match",
        "path_kind": "property"
      },
      "purpose": "Lists HTTP response statuses that produce the integration's no-match outcome.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/no_match/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 599
        },
        {
          "keyword": "minimum",
          "value": 100
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/shape",
        "path_kind": "property"
      },
      "purpose": "Declares whether a successful response is a singleton or a bounded collection.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/shape/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "singleton"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/shape/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "records",
            "cardinality"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/shape/oneOf/1/properties/cardinality",
        "path_kind": "property"
      },
      "purpose": "Requires two-record probing so collection results distinguish one match from ambiguity.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "probe_two"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/httpResponse/properties/shape/oneOf/1/properties/records",
        "path_kind": "property"
      },
      "purpose": "Selects the canonical response location containing collection records.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^/(?:[^/~]|~[01])+(?:/(?:[^/~]|~[01])+)*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/canonicalization",
        "path_kind": "property"
      },
      "purpose": "Selects the reviewed normalization rule applied before an input is compared, interpolated, or sent to a source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "identity",
            "ascii_lowercase"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/format",
        "path_kind": "property"
      },
      "purpose": "Applies the full-date semantic format to a string-valued integration input.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "date"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/maxLength",
        "path_kind": "property"
      },
      "purpose": "Caps a string-valued integration input at 1,024 Unicode scalar values, deriving its conservative 4,096-byte UTF-8 ceiling.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 1024
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/maximum",
        "path_kind": "property"
      },
      "purpose": "Sets the inclusive upper bound accepted for an integer-valued integration input.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 9007199254740991
        },
        {
          "keyword": "minimum",
          "value": -9007199254740991
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/minLength",
        "path_kind": "property"
      },
      "purpose": "Sets the minimum character length accepted for a string-valued integration input.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 16384
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/minimum",
        "path_kind": "property"
      },
      "purpose": "Sets the inclusive lower bound accepted for an integer-valued integration input.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 9007199254740991
        },
        {
          "keyword": "minimum",
          "value": -9007199254740991
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/pattern",
        "path_kind": "property"
      },
      "purpose": "Constrains a string-valued integration input with the authored regular expression.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 16384
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/role",
        "path_kind": "property"
      },
      "purpose": "Declares how one typed authoring input participates in source lookup, selection, or result shaping.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "selector",
            "parameter"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/input/properties/type",
        "path_kind": "property"
      },
      "purpose": "Declares the closed scalar or array type accepted for one integration input.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/scalarType",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/scalarType"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/inputOrLiteral/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Reference to a declared integration input.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/inputReference",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "input"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputReference"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/inputOrLiteral/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "boolean",
            "integer"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/inputReference/properties/input",
        "path_kind": "property"
      },
      "purpose": "Portable lowercase name for an integration input or output.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/inputName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputName"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/integrationRequestByteSize/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 1048576
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/integrationRequestByteSize/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,2}|10[0-1][0-9]|102[0-4])KiB|1MiB)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/integrationResponseByteSize/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 8388608
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/integrationResponseByteSize/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,2}|[1-7][0-9]{3}|80[0-9]{2}|81[0-8][0-9]|819[0-2])KiB|[1-8]MiB)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/integrationSourceByteSize/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 16777216
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/integrationSourceByteSize/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,3}|1[0-5][0-9]{3}|16[0-2][0-9]{2}|163[0-7][0-9]|1638[0-4])KiB|(?:[1-9]|1[0-6])MiB)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/limits/properties/calls",
        "path_kind": "property"
      },
      "purpose": "Caps the number of high-level source calls available to a script integration.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 16
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/limits/properties/deadline",
        "path_kind": "property"
      },
      "purpose": "Caps total integration execution time with a positive duration no greater than twenty seconds.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,3}|1[0-9]{4}|20000)ms|(?:[1-9]|1[0-9]|20)s)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/limits/properties/request_bytes",
        "path_kind": "property"
      },
      "purpose": "Maximum aggregate author-controlled request bytes for one execution, defaulting to 64 KiB and capped at 1 MiB. Use a positive byte integer or canonical KiB/MiB value.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer",
          "string"
        ],
        "local_reference": "#/$defs/integrationRequestByteSize",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "schema_value": "64KiB"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/integrationRequestByteSize"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/limits/properties/source_bytes",
        "path_kind": "property"
      },
      "purpose": "Maximum aggregate source-response bytes for one execution, defaulting to 2 MiB and capped at 16 MiB. Use a positive byte integer or canonical KiB/MiB value.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer",
          "string"
        ],
        "local_reference": "#/$defs/integrationSourceByteSize",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "schema_value": "2MiB"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/integrationSourceByteSize"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/notApplicable/properties/ambiguity",
        "path_kind": "property"
      },
      "purpose": "Why the reviewed source contract cannot produce more than one matching record.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/notApplicableReason",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "rationale",
            "request_fixture"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/notApplicableReason"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/notApplicable/properties/subject_mismatch",
        "path_kind": "property"
      },
      "purpose": "Why the reviewed response contract contains no identifier comparable with a requested selector.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/notApplicableReason",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "rationale",
            "request_fixture"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/notApplicableReason"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/notApplicableReason/properties/rationale",
        "path_kind": "property"
      },
      "purpose": "Why the named normally required outcome cannot occur for this source contract.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 512
        },
        {
          "keyword": "minLength",
          "value": 24
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/notApplicableReason/properties/request_fixture",
        "path_kind": "property"
      },
      "purpose": "Fixture name containing the supporting bounded source request.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/output/properties/format",
        "path_kind": "property"
      },
      "purpose": "Applies the full-date semantic format to a string-valued integration output.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "date"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/output/properties/maxLength",
        "path_kind": "property"
      },
      "purpose": "Caps the character length produced for a string-valued integration output.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 16384
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/output/properties/maximum",
        "path_kind": "property"
      },
      "purpose": "Sets the inclusive upper bound produced for an integer-valued integration output.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 9223372036854775807
        },
        {
          "keyword": "minimum",
          "value": -9223372036854775808
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/output/properties/minimum",
        "path_kind": "property"
      },
      "purpose": "Sets the inclusive lower bound produced for an integer-valued integration output.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 9223372036854775807
        },
        {
          "keyword": "minimum",
          "value": -9223372036854775808
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/output/properties/type",
        "path_kind": "property"
      },
      "purpose": "Supported scalar type, optionally paired with null for nullable values.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/scalarType",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/scalarType"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/output/properties/x-registry-source",
        "path_kind": "property"
      },
      "purpose": "Selects the canonical source-response location from which the HTTP output is extracted.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^/(?:[^/~]|~[01])+(?:/(?:[^/~]|~[01])+)*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci",
        "path_kind": "property"
      },
      "purpose": "Enables the bounded signed DCI search helper and declares its protocol and selector bindings.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "profile",
            "path",
            "jwks_profile",
            "sender",
            "receiver",
            "registry_type",
            "record_type",
            "locale",
            "selectors"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/jwks_profile",
        "path_kind": "property"
      },
      "purpose": "Selects the supported RSA signing-key-set profile used to verify signed DCI responses.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "rsa-signing-jwks-v1"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/locale",
        "path_kind": "property"
      },
      "purpose": "Declares the language or locale tag carried by signed DCI search requests.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z]{2,8}(?:-[A-Za-z0-9]{1,8})*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/path",
        "path_kind": "property"
      },
      "purpose": "Declares the exact private source path used for signed DCI search requests.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^/[^?#]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/profile",
        "path_kind": "property"
      },
      "purpose": "Selects the supported DCI search request profile used by the signed protocol helper.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "dci-search-v1"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/receiver",
        "path_kind": "property"
      },
      "purpose": "Declares the signed DCI receiver identifier included in protocol requests.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/record_type",
        "path_kind": "property"
      },
      "purpose": "Declares the record type requested through the signed DCI search profile.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/registry_type",
        "path_kind": "property"
      },
      "purpose": "Declares the registry type requested through the signed DCI search profile.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/selectors",
        "path_kind": "property"
      },
      "purpose": "Maps every selector input to its signed DCI request field and response location.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 8
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/selectors/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field",
            "response_pointer"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/selectors/additionalProperties/properties/field",
        "path_kind": "property"
      },
      "purpose": "Declares the signed DCI identifier field bound to one selector input.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 160
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/selectors/additionalProperties/properties/response_pointer",
        "path_kind": "property"
      },
      "purpose": "Selects the canonical signed-record response location used to recover one selector value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^/(?:[^/~]|~[01])+(?:/(?:[^/~]|~[01])+)*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/selectors/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Portable lowercase name for an integration input or output.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/inputName",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputName"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/protocol/properties/signed_dci/properties/sender",
        "path_kind": "property"
      },
      "purpose": "Declares the signed DCI sender identifier included in protocol requests.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/scalarType/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "string",
            "boolean",
            "integer"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/scalarType/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 2
        },
        {
          "keyword": "minItems",
          "value": 2
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/scalarType/oneOf/1/prefixItems/0",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "string",
            "boolean",
            "integer"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/scalarType/oneOf/1/prefixItems/1",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "null"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/allow",
        "path_kind": "property"
      },
      "purpose": "Constrains source access to the explicitly reviewed method and path templates in this integration contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/allow/items",
        "path_kind": "array_item"
      },
      "purpose": "One read-only upstream method and path pattern the adapter may call.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/allowRule",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "method",
            "path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/allowRule"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/auth",
        "path_kind": "property"
      },
      "purpose": "Declares the credential interface the source contract permits without embedding an environment credential value.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/credential",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/credential"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/product",
        "path_kind": "property"
      },
      "purpose": "Names the source product whose version labels are classified by this integration contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/protocol",
        "path_kind": "property"
      },
      "purpose": "Optional interoperable protocol profiles layered over the source transport.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/protocol",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/protocol"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/request_headers",
        "path_kind": "property"
      },
      "purpose": "Lists the bounded source request header names available to the integration adapter.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/request_headers/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z][A-Za-z0-9-]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/response",
        "path_kind": "property"
      },
      "purpose": "Defines the reviewed source response representation and optional byte bound.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/response/properties/format",
        "path_kind": "property"
      },
      "purpose": "Selects JSON decoding or text handling for reviewed source responses.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "json",
            "text"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/response/properties/max_bytes",
        "path_kind": "property"
      },
      "purpose": "Maximum bytes accepted from one source response, defaulting to 512 KiB and capped at 8 MiB. Use a positive byte integer or canonical KiB/MiB value.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer",
          "string"
        ],
        "local_reference": "#/$defs/integrationResponseByteSize",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "schema_value": "512KiB"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/integrationResponseByteSize"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/response_headers",
        "path_kind": "property"
      },
      "purpose": "Lists the bounded source response header names available to the integration adapter.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/response_headers/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z][A-Za-z0-9-]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/source/properties/versions",
        "path_kind": "property"
      },
      "purpose": "Source versions tested by the project and versions explicitly accepted as unverified.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/versions",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/versions"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versionList/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versions/anyOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "tested"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versions/anyOf/0/properties/tested",
        "path_kind": "property"
      },
      "purpose": "Requires at least one source product version to be classified as tested in this integration contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versions/anyOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "unverified"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versions/anyOf/1/properties/unverified",
        "path_kind": "property"
      },
      "purpose": "Requires at least one source product version to be classified as unverified in this integration contract.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versions/properties/tested",
        "path_kind": "property"
      },
      "purpose": "Bounded list of source version labels.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/versionList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/versionList"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/$defs/versions/properties/unverified",
        "path_kind": "property"
      },
      "purpose": "Bounded list of source version labels.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/versionList",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/versionList"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/capability",
        "path_kind": "property"
      },
      "purpose": "Exactly one bounded execution mechanism for the source adaptation.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/capability",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/capability"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/id",
        "path_kind": "property"
      },
      "purpose": "Stable project-local identifier for the integration.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/input",
        "path_kind": "property"
      },
      "purpose": "Typed selector and parameter inputs accepted by this integration.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/input/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Type, validation, and canonicalization rules for one authored input.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/input",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "role",
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/input"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/input/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Portable lowercase name for an integration input or output.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/inputName",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputName"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/limits",
        "path_kind": "property"
      },
      "purpose": "Optional tighter resource limits for one integration execution.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/limits",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/limits"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/not_applicable",
        "path_kind": "property"
      },
      "purpose": "Explicit rationale and request-fixture evidence for a normally required outcome that the source contract cannot produce.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/notApplicable",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/notApplicable"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs",
        "path_kind": "property"
      },
      "purpose": "Named typed outputs, or a shorthand list of output names inferred by the authoring compiler.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array",
          "object"
        ],
        "composed": true
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/0/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Type and optional source pointer for one normalized integration output.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/output",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/output"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/0/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": true
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/0/propertyNames/allOf/0",
        "path_kind": "branch"
      },
      "purpose": "Portable lowercase name for an integration input or output.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/inputName",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputName"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/0/propertyNames/allOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/0/propertyNames/allOf/1/not",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "matched",
            "outcome"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 64
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/outputs/oneOf/1/items",
        "path_kind": "array_item"
      },
      "purpose": "Portable lowercase name for an integration input or output.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/inputName",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/inputName"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/revision",
        "path_kind": "property"
      },
      "purpose": "Monotonically increasing revision of this integration contract.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/source",
        "path_kind": "property"
      },
      "purpose": "Optional source product metadata and transport policy; capabilities remain product-neutral.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/source",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "auth"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "integration",
        "pointer": "/$defs/source"
      }
    },
    {
      "address": {
        "schema": "integration",
        "pointer": "/properties/version",
        "path_kind": "property"
      },
      "purpose": "Integration authoring format version.",
      "purpose_source": "schema_description",
      "semantic_owner": "integration_contract",
      "human_owner": "integration_maintainers",
      "scope": "A reviewed source contract, bounded adaptation capability, typed inputs and outputs, and offline verification requirements.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "public",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "notary",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "fixture_execution",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.integration.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a bounded synthetic source contract and fixture-safe values that demonstrate behavior without revealing a country endpoint or record.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Update affected fixtures and rebuild the project; re-review authority whenever source access, credentials, or bounds change.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "registry_notary",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "notary_config",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "security",
        "privacy",
        "relay",
        "notary",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "",
        "path_kind": "root"
      },
      "purpose": "Defines one synthetic, deterministic integration scenario for offline adapter verification.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "classification",
            "input",
            "interactions",
            "expect"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/expectation/properties/claims",
        "path_kind": "property"
      },
      "purpose": "States the synthetic Notary claim outcomes expected after the reviewed Relay consultation behavior.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/expectation/properties/error",
        "path_kind": "property"
      },
      "purpose": "States the bounded error identifier expected from a failing offline fixture.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/expectation/properties/outcome",
        "path_kind": "property"
      },
      "purpose": "States whether the offline fixture is expected to match, find no match, or remain ambiguous.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "match",
            "no_match",
            "ambiguous"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/expectation/properties/outputs",
        "path_kind": "property"
      },
      "purpose": "Maps integration output names to the synthetic values expected after fixture execution.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/fixtureBody/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/fixtureBody/oneOf/0/properties/file",
        "path_kind": "property"
      },
      "purpose": "Selects a fixture-local synthetic body file beneath the reserved bodies directory.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 8
        },
        {
          "keyword": "pattern",
          "value": "^bodies/(?!\\.\\.?/)(?!.*(?:/)\\.\\.?/)(?!.*//).+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/fixtureBody/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/fixtureBody/oneOf/1/not",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedClaimRef/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedClaimRef/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedClaimRef/oneOf/1/properties/id",
        "path_kind": "property"
      },
      "purpose": "Names one authored claim requested by this fixture witness.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedClaimRef/oneOf/1/properties/version",
        "path_kind": "property"
      },
      "purpose": "Pins the requested claim to one authored claim-policy version.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedIdentifier/properties/scheme",
        "path_kind": "property"
      },
      "purpose": "Names the authored identifier scheme selected by a consultation input mapping.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 96
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedIdentifier/properties/value",
        "path_kind": "property"
      },
      "purpose": "Supplies the synthetic string value bound to this identifier scheme.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/claims",
        "path_kind": "property"
      },
      "purpose": "Lists the authored claims evaluated by this synthetic request witness.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 64
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/claims/items",
        "path_kind": "array_item"
      },
      "purpose": "A requested claim ID, optionally pinned to one authored claim version.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object",
          "string"
        ],
        "local_reference": "#/$defs/governedClaimRef",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "array_items_share_element_contract"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/governedClaimRef"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/disclosure",
        "path_kind": "property"
      },
      "purpose": "Selects the disclosure mode requested from the authored claim policy.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/format",
        "path_kind": "property"
      },
      "purpose": "Selects the claim-result media type requested from the governed Notary path.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/purpose",
        "path_kind": "property"
      },
      "purpose": "Names the authored service purpose exercised by this synthetic request witness.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/target",
        "path_kind": "property"
      },
      "purpose": "The synthetic subject target presented to the same governed request boundary as a live Notary evaluation.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/governedTarget",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/variables",
        "path_kind": "property"
      },
      "purpose": "Supplies synthetic date variables to the governed evaluation request.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/variables/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "date"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest/properties/variables/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget/properties/attributes",
        "path_kind": "property"
      },
      "purpose": "Supplies independently authored typed target attributes for consultation input mapping.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget/properties/attributes/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "boolean",
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget/properties/id",
        "path_kind": "property"
      },
      "purpose": "Supplies an optional synthetic direct target identifier.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget/properties/identifiers",
        "path_kind": "property"
      },
      "purpose": "Supplies independently authored synthetic identifiers for consultation input mapping.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget/properties/identifiers/items",
        "path_kind": "array_item"
      },
      "purpose": "One synthetic target identifier with an authored scheme and string value.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/governedIdentifier",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "scheme",
            "value"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/governedIdentifier"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/governedTarget/properties/type",
        "path_kind": "property"
      },
      "purpose": "Names the authored target entity type used for claim evaluation.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 64
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/interaction/properties/expect",
        "path_kind": "property"
      },
      "purpose": "Exact HTTP request shape the adapter must produce.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/request",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "method",
            "path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/request"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/interaction/properties/respond",
        "path_kind": "property"
      },
      "purpose": "Synthetic HTTP response or timeout returned to the adapter.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/response",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/response"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/body",
        "path_kind": "property"
      },
      "purpose": "Defines the synthetic request body expectation or fixture-local file reference without reading a source.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/fixtureBody",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/fixtureBody"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/headers",
        "path_kind": "property"
      },
      "purpose": "States the synthetic request headers expected from one offline fixture interaction.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/headers/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 8192
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/headers/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z][A-Za-z0-9-]{0,63}$"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/method",
        "path_kind": "property"
      },
      "purpose": "States the synthetic request method expected from the offline integration fixture.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "GET",
            "POST"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/path",
        "path_kind": "property"
      },
      "purpose": "States the synthetic request path expected from the offline integration fixture.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 4096
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^/[^?#]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/query",
        "path_kind": "property"
      },
      "purpose": "States the synthetic query parameters expected from one offline fixture interaction.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/query/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "array",
          "boolean",
          "integer",
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "not_applicable",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/query/additionalProperties/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "boolean",
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/query/additionalProperties/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 64
        },
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/request/properties/query/additionalProperties/oneOf/1/items",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "boolean",
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "status"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/0/properties/body",
        "path_kind": "property"
      },
      "purpose": "Defines the synthetic response body returned by the offline fixture harness to the integration.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/fixtureBody",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/fixtureBody"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/0/properties/headers",
        "path_kind": "property"
      },
      "purpose": "Defines the synthetic HTTP response headers returned by the offline fixture harness.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 32
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/0/properties/headers/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 8192
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/0/properties/status",
        "path_kind": "property"
      },
      "purpose": "Selects the synthetic HTTP status returned by the offline fixture harness.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 599
        },
        {
          "keyword": "minimum",
          "value": 100
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "timeout"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/$defs/response/oneOf/1/properties/timeout",
        "path_kind": "property"
      },
      "purpose": "Records bounded synthetic timeout intent; offline execution returns the timeout outcome without waiting for the authored interval.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,3}|1[0-9]{4}|20000)ms|(?:[1-9]|1[0-9]|20)s)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/classification",
        "path_kind": "property"
      },
      "purpose": "Declares that fixture data is synthetic and safe for offline testing.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "public",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "synthetic"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/expect",
        "path_kind": "property"
      },
      "purpose": "Observable adapter result required for the scenario to pass.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/expectation",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/expectation"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/input",
        "path_kind": "property"
      },
      "purpose": "Typed consultation inputs supplied to the adapter under test.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/input/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "boolean",
          "integer",
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "boolean",
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/input/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/interactions",
        "path_kind": "property"
      },
      "purpose": "Ordered upstream request and response exchanges expected during execution.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 16
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/interactions/items",
        "path_kind": "array_item"
      },
      "purpose": "One expected upstream request paired with its synthetic response.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/interaction",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "expect",
            "respond"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/interaction"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/name",
        "path_kind": "property"
      },
      "purpose": "Human-readable scenario name shown in test output.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "public",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/request",
        "path_kind": "property"
      },
      "purpose": "Optional independently authored synthetic Notary request used to prove the request-to-consultation binding before Relay access.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/governedRequest",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "target",
            "claims",
            "purpose"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "fixture",
        "pointer": "/$defs/governedRequest"
      }
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/variables",
        "path_kind": "property"
      },
      "purpose": "Named date values available to deterministic fixture interpolation.",
      "purpose_source": "schema_description",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 16
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/variables/additionalProperties",
        "path_kind": "map_value"
      },
      "purpose": "Defines the contract shared by every author-controlled value in the enclosing typed map.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "date"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "fixture",
        "pointer": "/properties/variables/propertyNames",
        "path_kind": "map_key"
      },
      "purpose": "Names one author-controlled entry in the enclosing typed map; the key is data, not an extension field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "fixture_harness",
      "human_owner": "test_maintainers",
      "scope": "An offline synthetic interaction and expected outcome used to verify one integration contract without source access.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "environment_independent",
      "sensitivity": "redacted_fixture",
      "state": "authored",
      "products": [
        "registryctl",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "fixture_execution"
      ],
      "diagnostic": "registryctl.authoring.fixture.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use unmistakably synthetic inputs, requests, responses, claims, and errors; fixtures must not contain copied personal or source data.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "update_fixtures",
      "migration_note": "Update the fixture when the reviewed integration contract changes, while preserving synthetic and non-sensitive test data.",
      "consumers": [
        "registryctl_authoring",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "fixture_report",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "compatibility",
        "documentation",
        "testing"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "synthetic_fixture_value_redacted",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "",
        "path_kind": "root"
      },
      "purpose": "Defines a bounded, materialized entity that Relay can query without coupling the project to a specific source product.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "version",
            "id",
            "revision",
            "primary_key",
            "schema",
            "materialization"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/const",
        "path_kind": "property"
      },
      "purpose": "Requires one entity field to equal the single authored value supplied by this schema constraint.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/enum",
        "path_kind": "property"
      },
      "purpose": "Restricts one entity field to the unique authored values listed by this schema constraint.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/format",
        "path_kind": "property"
      },
      "purpose": "Adds a reviewed semantic format constraint to one string-valued entity field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "date"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/maxLength",
        "path_kind": "property"
      },
      "purpose": "Caps the character length accepted for one string-valued entity field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 65536
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/maximum",
        "path_kind": "property"
      },
      "purpose": "Sets the inclusive upper numeric bound accepted for one entity field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 9007199254740991
        },
        {
          "keyword": "minimum",
          "value": -9007199254740991
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/minLength",
        "path_kind": "property"
      },
      "purpose": "Sets the minimum character length accepted for one string-valued entity field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 65536
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/minimum",
        "path_kind": "property"
      },
      "purpose": "Sets the inclusive lower numeric bound accepted for one entity field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 9007199254740991
        },
        {
          "keyword": "minimum",
          "value": -9007199254740991
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/pattern",
        "path_kind": "property"
      },
      "purpose": "Constrains a string-valued entity field with the authored regular expression.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 1024
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema/properties/type",
        "path_kind": "property"
      },
      "purpose": "Declares the closed scalar, array, or object type accepted for one entity field.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/scalarType",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/scalarType"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/additionalProperties",
        "path_kind": "property"
      },
      "purpose": "Controls whether the entity object accepts fields outside its declared closed property set.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": false
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/properties",
        "path_kind": "property"
      },
      "purpose": "Maps every declared entity property name to its closed field schema.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxProperties",
          "value": 256
        },
        {
          "keyword": "minProperties",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/properties/additionalProperties",
        "path_kind": "property"
      },
      "purpose": "Bounded schema keywords supported for one scalar materialized field.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/fieldSchema",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/fieldSchema"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/properties/propertyNames",
        "path_kind": "property"
      },
      "purpose": "Portable lowercase record field name.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/propertyName",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/propertyName"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/required",
        "path_kind": "property"
      },
      "purpose": "Lists the entity properties that every validated materialized record must contain.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 256
        },
        {
          "keyword": "minItems",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/required/items",
        "path_kind": "array_item"
      },
      "purpose": "Portable lowercase record field name.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/propertyName",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/propertyName"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema/properties/type",
        "path_kind": "property"
      },
      "purpose": "Declares the materialized entity record schema as an object.",
      "purpose_source": "reviewed_override",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/scalarType/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "string",
            "boolean",
            "integer"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/scalarType/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maxItems",
          "value": 2
        },
        {
          "keyword": "minItems",
          "value": 2
        },
        {
          "keyword": "type",
          "value": "array"
        },
        {
          "keyword": "uniqueItems",
          "value": true
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/scalarType/oneOf/1/prefixItems/0",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "string",
            "boolean",
            "integer"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/$defs/scalarType/oneOf/1/prefixItems/1",
        "path_kind": "array_item"
      },
      "purpose": "Defines the contract shared by each ordered item in the enclosing authored list.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "null"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/id",
        "path_kind": "property"
      },
      "purpose": "Stable project-local identifier for the entity.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization",
        "path_kind": "property"
      },
      "purpose": "Authored resource, refresh, and bounded recovery-set retention applied while building entity generations.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "max_records",
            "max_bytes",
            "refresh",
            "retain_generations"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/max_bytes",
        "path_kind": "property"
      },
      "purpose": "Maximum encoded size of one generation, up to 1 GiB, as bytes or a KiB/MiB quantity.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer",
          "string"
        ],
        "composed": true
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/max_bytes/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 1073741824
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/max_bytes/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,5}|10[0-3][0-9]{4}|104[0-7][0-9]{3}|1048[0-4][0-9]{2}|10485[0-6][0-9]|104857[0-6])KiB|(?:[1-9][0-9]{0,2}|10[0-1][0-9]|102[0-4])MiB)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/max_records",
        "path_kind": "property"
      },
      "purpose": "Maximum number of records allowed in one generation.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 100000000
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/refresh",
        "path_kind": "property"
      },
      "purpose": "Refresh cadence as a canonical positive duration no greater than 30 days, or manual when an operator initiates every refresh.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": true
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": []
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/refresh/oneOf/0",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "manual"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/refresh/oneOf/1",
        "path_kind": "branch"
      },
      "purpose": "Documents a validation alternative or condition and is not authored as a standalone configuration field.",
      "purpose_source": "structural_taxonomy",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "structural",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "branch_has_no_authored_value"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^(?:(?:[1-9][0-9]{0,8}|1[0-9]{9}|2[0-4][0-9]{8}|25[0-8][0-9]{7}|259[0-1][0-9]{6}|2592000000)ms|(?:[1-9][0-9]{0,5}|1[0-9]{6}|2[0-4][0-9]{5}|25[0-8][0-9]{4}|259[0-1][0-9]{3}|2592000)s|(?:[1-9][0-9]{0,3}|[1-3][0-9]{4}|4[0-2][0-9]{3}|43[0-1][0-9]{2}|43200)m|(?:[1-9][0-9]{0,1}|[1-6][0-9]{2}|7[0-1][0-9]{1}|720)h|(?:[1-9][0-9]{0,0}|[1-2][0-9]{1}|30)d)$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/materialization/properties/retain_generations",
        "path_kind": "property"
      },
      "purpose": "Number of completed cache generations, including the active generation, retained as a bounded recovery set after successful publication. This does not make arbitrary retained generations selectable for rollback.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 16
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/primary_key",
        "path_kind": "property"
      },
      "purpose": "Field whose value uniquely identifies each materialized record.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/stableId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/stableId"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/revision",
        "path_kind": "property"
      },
      "purpose": "Monotonically increasing revision of this entity definition.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": true,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/schema",
        "path_kind": "property"
      },
      "purpose": "Closed JSON object schema for materialized records.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/objectSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "internal",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "additionalProperties",
            "required",
            "properties"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "entity",
        "pointer": "/$defs/objectSchema"
      }
    },
    {
      "address": {
        "schema": "entity",
        "pointer": "/properties/version",
        "path_kind": "property"
      },
      "purpose": "Entity authoring format version.",
      "purpose_source": "schema_description",
      "semantic_owner": "entity_contract",
      "human_owner": "data_model_maintainers",
      "scope": "A materialized entity identity, closed record shape, governance metadata, and refresh or size constraints.",
      "field_type": {
        "schema_types": [],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "public",
      "state": "authored",
      "products": [
        "registryctl",
        "relay",
        "editor",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "cross_file_semantic",
        "product_build"
      ],
      "diagnostic": "registryctl.authoring.entity.invalid",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use a minimal synthetic entity with non-identifying field names and values from a maintained golden workspace.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "rebuild_project",
      "migration_note": "Rebuild the project and review storage, disclosure, and compatibility impact when an entity contract changes.",
      "consumers": [
        "registryctl_authoring",
        "registry_relay",
        "editor_tooling",
        "docs_generator"
      ],
      "generated_artifacts": [
        "editor_schemas",
        "project_build",
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "privacy",
        "relay",
        "compatibility",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": 1
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "",
        "key_path": "",
        "path_kind": "root"
      },
      "purpose": "Root configuration document. Parsed from YAML at startup.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_root_structural",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "server",
            "catalog",
            "auth",
            "audit",
            "datasets"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/aggregate_only_execution",
        "key_path": "datasets[].aggregates[].access.aggregate_only_execution",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/aggregate_only_execution",
        "key_path": "datasets[].entities[].aggregates[].access.aggregate_only_execution",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/aggregate_only_execution",
        "key_path": "datasets[].tables[].aggregates[].access.aggregate_only_execution",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/aggregate_scope",
        "key_path": "datasets[].aggregates[].access.aggregate_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/aggregate_scope",
        "key_path": "datasets[].entities[].aggregates[].access.aggregate_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/aggregate_scope",
        "key_path": "datasets[].tables[].aggregates[].access.aggregate_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/metadata_scope",
        "key_path": "datasets[].aggregates[].access.metadata_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/metadata_scope",
        "key_path": "datasets[].entities[].aggregates[].access.metadata_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateAccessConfig/properties/metadata_scope",
        "key_path": "datasets[].tables[].aggregates[].access.metadata_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/access",
        "key_path": "datasets[].aggregates[].access",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/access",
        "key_path": "datasets[].entities[].aggregates[].access",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/access",
        "key_path": "datasets[].tables[].aggregates[].access",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/allowed_filters",
        "key_path": "datasets[].aggregates[].allowed_filters",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/allowed_filters",
        "key_path": "datasets[].entities[].aggregates[].allowed_filters",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/allowed_filters",
        "key_path": "datasets[].tables[].aggregates[].allowed_filters",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/allowed_filters/items",
        "key_path": "datasets[].aggregates[].allowed_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "A single allowed filter: field name + permitted operators.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AllowedFilter",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field",
            "ops"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/allowed_filters/items",
        "key_path": "datasets[].entities[].aggregates[].allowed_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "A single allowed filter: field name + permitted operators.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AllowedFilter",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field",
            "ops"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/allowed_filters/items",
        "key_path": "datasets[].tables[].aggregates[].allowed_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "A single allowed filter: field name + permitted operators.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AllowedFilter",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field",
            "ops"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/default_group_by",
        "key_path": "datasets[].aggregates[].default_group_by",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/default_group_by",
        "key_path": "datasets[].entities[].aggregates[].default_group_by",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/default_group_by",
        "key_path": "datasets[].tables[].aggregates[].default_group_by",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/default_group_by/items",
        "key_path": "datasets[].aggregates[].default_group_by[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/default_group_by/items",
        "key_path": "datasets[].entities[].aggregates[].default_group_by[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/default_group_by/items",
        "key_path": "datasets[].tables[].aggregates[].default_group_by[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/description",
        "key_path": "datasets[].aggregates[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/description",
        "key_path": "datasets[].entities[].aggregates[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/description",
        "key_path": "datasets[].tables[].aggregates[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/dimensions",
        "key_path": "datasets[].aggregates[].dimensions",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/dimensions",
        "key_path": "datasets[].entities[].aggregates[].dimensions",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/dimensions",
        "key_path": "datasets[].tables[].aggregates[].dimensions",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/dimensions/items",
        "key_path": "datasets[].aggregates[].dimensions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateDimensionConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/dimensions/items",
        "key_path": "datasets[].entities[].aggregates[].dimensions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateDimensionConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/dimensions/items",
        "key_path": "datasets[].tables[].aggregates[].dimensions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateDimensionConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/disclosure_control",
        "key_path": "datasets[].aggregates[].disclosure_control",
        "path_kind": "property"
      },
      "purpose": "Disclosure control settings per aggregate. Defaults to\n`min_group_size: 5`, `suppression: omit`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DisclosureControlConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/disclosure_control",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control",
        "path_kind": "property"
      },
      "purpose": "Disclosure control settings per aggregate. Defaults to\n`min_group_size: 5`, `suppression: omit`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DisclosureControlConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/disclosure_control",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control",
        "path_kind": "property"
      },
      "purpose": "Disclosure control settings per aggregate. Defaults to\n`min_group_size: 5`, `suppression: omit`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DisclosureControlConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/group_by",
        "key_path": "datasets[].aggregates[].group_by",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/group_by",
        "key_path": "datasets[].entities[].aggregates[].group_by",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/group_by",
        "key_path": "datasets[].tables[].aggregates[].group_by",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/group_by/items",
        "key_path": "datasets[].aggregates[].group_by[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/group_by/items",
        "key_path": "datasets[].entities[].aggregates[].group_by[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/group_by/items",
        "key_path": "datasets[].tables[].aggregates[].group_by[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/id",
        "key_path": "datasets[].aggregates[].id",
        "path_kind": "property"
      },
      "purpose": "Aggregate identifier within a resource.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/id",
        "key_path": "datasets[].entities[].aggregates[].id",
        "path_kind": "property"
      },
      "purpose": "Aggregate identifier within a resource.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/id",
        "key_path": "datasets[].tables[].aggregates[].id",
        "path_kind": "property"
      },
      "purpose": "Aggregate identifier within a resource.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/indicators",
        "key_path": "datasets[].aggregates[].indicators",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/indicators",
        "key_path": "datasets[].entities[].aggregates[].indicators",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/indicators",
        "key_path": "datasets[].tables[].aggregates[].indicators",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/indicators/items",
        "key_path": "datasets[].aggregates[].indicators[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateIndicatorConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "function",
            "column",
            "unit_measure"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/indicators/items",
        "key_path": "datasets[].entities[].aggregates[].indicators[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateIndicatorConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "function",
            "column",
            "unit_measure"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/indicators/items",
        "key_path": "datasets[].tables[].aggregates[].indicators[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateIndicatorConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "label",
            "function",
            "column",
            "unit_measure"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/joins",
        "key_path": "datasets[].aggregates[].joins",
        "path_kind": "property"
      },
      "purpose": "Legacy entity-local aggregate fields. These stay parseable while\nthe public surface moves to dataset-level aggregates.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/joins",
        "key_path": "datasets[].entities[].aggregates[].joins",
        "path_kind": "property"
      },
      "purpose": "Legacy entity-local aggregate fields. These stay parseable while\nthe public surface moves to dataset-level aggregates.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/joins",
        "key_path": "datasets[].tables[].aggregates[].joins",
        "path_kind": "property"
      },
      "purpose": "Legacy entity-local aggregate fields. These stay parseable while\nthe public surface moves to dataset-level aggregates.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/joins/items",
        "key_path": "datasets[].aggregates[].joins[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateJoinConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relationship"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateJoinConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/joins/items",
        "key_path": "datasets[].entities[].aggregates[].joins[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateJoinConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relationship"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateJoinConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/joins/items",
        "key_path": "datasets[].tables[].aggregates[].joins[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateJoinConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relationship"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateJoinConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/measures",
        "key_path": "datasets[].aggregates[].measures",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/measures",
        "key_path": "datasets[].entities[].aggregates[].measures",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/measures",
        "key_path": "datasets[].tables[].aggregates[].measures",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/measures/items",
        "key_path": "datasets[].aggregates[].measures[]",
        "path_kind": "array_item"
      },
      "purpose": "One measure inside an aggregate.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateMeasure",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "function",
            "column"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/measures/items",
        "key_path": "datasets[].entities[].aggregates[].measures[]",
        "path_kind": "array_item"
      },
      "purpose": "One measure inside an aggregate.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateMeasure",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "function",
            "column"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/measures/items",
        "key_path": "datasets[].tables[].aggregates[].measures[]",
        "path_kind": "array_item"
      },
      "purpose": "One measure inside an aggregate.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateMeasure",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "function",
            "column"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filter_bindings",
        "key_path": "datasets[].aggregates[].required_filter_bindings",
        "path_kind": "property"
      },
      "purpose": "Principal-derived bindings that both satisfy the required filter gate\nand are applied to the aggregate query.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filter_bindings",
        "key_path": "datasets[].entities[].aggregates[].required_filter_bindings",
        "path_kind": "property"
      },
      "purpose": "Principal-derived bindings that both satisfy the required filter gate\nand are applied to the aggregate query.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filter_bindings",
        "key_path": "datasets[].tables[].aggregates[].required_filter_bindings",
        "path_kind": "property"
      },
      "purpose": "Principal-derived bindings that both satisfy the required filter gate\nand are applied to the aggregate query.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filter_bindings/items",
        "key_path": "datasets[].aggregates[].required_filter_bindings[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filter_bindings/items",
        "key_path": "datasets[].entities[].aggregates[].required_filter_bindings[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filter_bindings/items",
        "key_path": "datasets[].tables[].aggregates[].required_filter_bindings[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filters",
        "key_path": "datasets[].aggregates[].required_filters",
        "path_kind": "property"
      },
      "purpose": "Alternative fields or dimensions that can satisfy the aggregate gate. A\nprincipal-bound equality filter on any listed field is sufficient, so\nlist multiple fields only when each is an acceptable boundary.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filters",
        "key_path": "datasets[].entities[].aggregates[].required_filters",
        "path_kind": "property"
      },
      "purpose": "Alternative fields or dimensions that can satisfy the aggregate gate. A\nprincipal-bound equality filter on any listed field is sufficient, so\nlist multiple fields only when each is an acceptable boundary.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filters",
        "key_path": "datasets[].tables[].aggregates[].required_filters",
        "path_kind": "property"
      },
      "purpose": "Alternative fields or dimensions that can satisfy the aggregate gate. A\nprincipal-bound equality filter on any listed field is sufficient, so\nlist multiple fields only when each is an acceptable boundary.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filters/items",
        "key_path": "datasets[].aggregates[].required_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filters/items",
        "key_path": "datasets[].entities[].aggregates[].required_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/required_filters/items",
        "key_path": "datasets[].tables[].aggregates[].required_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/source_entity",
        "key_path": "datasets[].aggregates[].source_entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/source_entity",
        "key_path": "datasets[].entities[].aggregates[].source_entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/source_entity",
        "key_path": "datasets[].tables[].aggregates[].source_entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/spatial",
        "key_path": "datasets[].aggregates[].spatial",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "mode",
            "dimension",
            "geometry_entity",
            "geometry_id_field",
            "geometry_field"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/spatial",
        "key_path": "datasets[].entities[].aggregates[].spatial",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "mode",
            "dimension",
            "geometry_entity",
            "geometry_id_field",
            "geometry_field"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/spatial",
        "key_path": "datasets[].tables[].aggregates[].spatial",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "mode",
            "dimension",
            "geometry_entity",
            "geometry_id_field",
            "geometry_field"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/temporal_field",
        "key_path": "datasets[].aggregates[].temporal_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/temporal_field",
        "key_path": "datasets[].entities[].aggregates[].temporal_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/temporal_field",
        "key_path": "datasets[].tables[].aggregates[].temporal_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/title",
        "key_path": "datasets[].aggregates[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/title",
        "key_path": "datasets[].entities[].aggregates[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig/properties/title",
        "key_path": "datasets[].tables[].aggregates[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/codelist",
        "key_path": "datasets[].aggregates[].dimensions[].codelist",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/codelist",
        "key_path": "datasets[].entities[].aggregates[].dimensions[].codelist",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/codelist",
        "key_path": "datasets[].tables[].aggregates[].dimensions[].codelist",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/field",
        "key_path": "datasets[].aggregates[].dimensions[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/field",
        "key_path": "datasets[].entities[].aggregates[].dimensions[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/field",
        "key_path": "datasets[].tables[].aggregates[].dimensions[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/id",
        "key_path": "datasets[].aggregates[].dimensions[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/id",
        "key_path": "datasets[].entities[].aggregates[].dimensions[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/id",
        "key_path": "datasets[].tables[].aggregates[].dimensions[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/label",
        "key_path": "datasets[].aggregates[].dimensions[].label",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/label",
        "key_path": "datasets[].entities[].aggregates[].dimensions[].label",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateDimensionConfig/properties/label",
        "key_path": "datasets[].tables[].aggregates[].dimensions[].label",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/column",
        "key_path": "datasets[].aggregates[].indicators[].column",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/column",
        "key_path": "datasets[].entities[].aggregates[].indicators[].column",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/column",
        "key_path": "datasets[].tables[].aggregates[].indicators[].column",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/decimals",
        "key_path": "datasets[].aggregates[].indicators[].decimals",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/decimals",
        "key_path": "datasets[].entities[].aggregates[].indicators[].decimals",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/decimals",
        "key_path": "datasets[].tables[].aggregates[].indicators[].decimals",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/definition_uri",
        "key_path": "datasets[].aggregates[].indicators[].definition_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/definition_uri",
        "key_path": "datasets[].entities[].aggregates[].indicators[].definition_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/definition_uri",
        "key_path": "datasets[].tables[].aggregates[].indicators[].definition_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/frequency",
        "key_path": "datasets[].aggregates[].indicators[].frequency",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/frequency",
        "key_path": "datasets[].entities[].aggregates[].indicators[].frequency",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/frequency",
        "key_path": "datasets[].tables[].aggregates[].indicators[].frequency",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/function",
        "key_path": "datasets[].aggregates[].indicators[].function",
        "path_kind": "property"
      },
      "purpose": "Aggregate function. V1 supports the basic set plus the\noptional functions (`median`, `count_distinct`, `stddev`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateFunction"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/function",
        "key_path": "datasets[].entities[].aggregates[].indicators[].function",
        "path_kind": "property"
      },
      "purpose": "Aggregate function. V1 supports the basic set plus the\noptional functions (`median`, `count_distinct`, `stddev`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateFunction"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/function",
        "key_path": "datasets[].tables[].aggregates[].indicators[].function",
        "path_kind": "property"
      },
      "purpose": "Aggregate function. V1 supports the basic set plus the\noptional functions (`median`, `count_distinct`, `stddev`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateFunction"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/id",
        "key_path": "datasets[].aggregates[].indicators[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/id",
        "key_path": "datasets[].entities[].aggregates[].indicators[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/id",
        "key_path": "datasets[].tables[].aggregates[].indicators[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/label",
        "key_path": "datasets[].aggregates[].indicators[].label",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/label",
        "key_path": "datasets[].entities[].aggregates[].indicators[].label",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/label",
        "key_path": "datasets[].tables[].aggregates[].indicators[].label",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/unit_measure",
        "key_path": "datasets[].aggregates[].indicators[].unit_measure",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/unit_measure",
        "key_path": "datasets[].entities[].aggregates[].indicators[].unit_measure",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/unit_measure",
        "key_path": "datasets[].tables[].aggregates[].indicators[].unit_measure",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/unit_mult",
        "key_path": "datasets[].aggregates[].indicators[].unit_mult",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int32"
        },
        {
          "keyword": "maximum",
          "value": 2147483647
        },
        {
          "keyword": "minimum",
          "value": -2147483648
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/unit_mult",
        "key_path": "datasets[].entities[].aggregates[].indicators[].unit_mult",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int32"
        },
        {
          "keyword": "maximum",
          "value": 2147483647
        },
        {
          "keyword": "minimum",
          "value": -2147483648
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateIndicatorConfig/properties/unit_mult",
        "key_path": "datasets[].tables[].aggregates[].indicators[].unit_mult",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int32"
        },
        {
          "keyword": "maximum",
          "value": 2147483647
        },
        {
          "keyword": "minimum",
          "value": -2147483648
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateJoinConfig/properties/relationship",
        "key_path": "datasets[].aggregates[].joins[].relationship",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateJoinConfig/properties/relationship",
        "key_path": "datasets[].entities[].aggregates[].joins[].relationship",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateJoinConfig/properties/relationship",
        "key_path": "datasets[].tables[].aggregates[].joins[].relationship",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/column",
        "key_path": "datasets[].aggregates[].measures[].column",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/column",
        "key_path": "datasets[].entities[].aggregates[].measures[].column",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/column",
        "key_path": "datasets[].tables[].aggregates[].measures[].column",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/function",
        "key_path": "datasets[].aggregates[].measures[].function",
        "path_kind": "property"
      },
      "purpose": "Aggregate function. V1 supports the basic set plus the\noptional functions (`median`, `count_distinct`, `stddev`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateFunction"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/function",
        "key_path": "datasets[].entities[].aggregates[].measures[].function",
        "path_kind": "property"
      },
      "purpose": "Aggregate function. V1 supports the basic set plus the\noptional functions (`median`, `count_distinct`, `stddev`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateFunction"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/function",
        "key_path": "datasets[].tables[].aggregates[].measures[].function",
        "path_kind": "property"
      },
      "purpose": "Aggregate function. V1 supports the basic set plus the\noptional functions (`median`, `count_distinct`, `stddev`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AggregateFunction",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "count",
            "sum",
            "avg",
            "min",
            "max",
            "median",
            "count_distinct",
            "stddev"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateFunction"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/name",
        "key_path": "datasets[].aggregates[].measures[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/name",
        "key_path": "datasets[].entities[].aggregates[].measures[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateMeasure/properties/name",
        "key_path": "datasets[].tables[].aggregates[].measures[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/bbox_fields",
        "key_path": "datasets[].aggregates[].spatial.bbox_fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "min_x",
            "min_y",
            "max_x",
            "max_y"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/bbox_fields",
        "key_path": "datasets[].entities[].aggregates[].spatial.bbox_fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "min_x",
            "min_y",
            "max_x",
            "max_y"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/bbox_fields",
        "key_path": "datasets[].tables[].aggregates[].spatial.bbox_fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "min_x",
            "min_y",
            "max_x",
            "max_y"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/collection_id",
        "key_path": "datasets[].aggregates[].spatial.collection_id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/collection_id",
        "key_path": "datasets[].entities[].aggregates[].spatial.collection_id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/collection_id",
        "key_path": "datasets[].tables[].aggregates[].spatial.collection_id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/dimension",
        "key_path": "datasets[].aggregates[].spatial.dimension",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/dimension",
        "key_path": "datasets[].entities[].aggregates[].spatial.dimension",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/dimension",
        "key_path": "datasets[].tables[].aggregates[].spatial.dimension",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_entity",
        "key_path": "datasets[].aggregates[].spatial.geometry_entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_entity",
        "key_path": "datasets[].entities[].aggregates[].spatial.geometry_entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_entity",
        "key_path": "datasets[].tables[].aggregates[].spatial.geometry_entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_field",
        "key_path": "datasets[].aggregates[].spatial.geometry_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_field",
        "key_path": "datasets[].entities[].aggregates[].spatial.geometry_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_field",
        "key_path": "datasets[].tables[].aggregates[].spatial.geometry_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_id_field",
        "key_path": "datasets[].aggregates[].spatial.geometry_id_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_id_field",
        "key_path": "datasets[].entities[].aggregates[].spatial.geometry_id_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/geometry_id_field",
        "key_path": "datasets[].tables[].aggregates[].spatial.geometry_id_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/max_geometry_vertices",
        "key_path": "datasets[].aggregates[].spatial.max_geometry_vertices",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/max_geometry_vertices",
        "key_path": "datasets[].entities[].aggregates[].spatial.max_geometry_vertices",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/max_geometry_vertices",
        "key_path": "datasets[].tables[].aggregates[].spatial.max_geometry_vertices",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/mode",
        "key_path": "datasets[].aggregates[].spatial.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "admin_area"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/mode",
        "key_path": "datasets[].entities[].aggregates[].spatial.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "admin_area"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AggregateSpatialConfig/oneOf/0/properties/mode",
        "key_path": "datasets[].tables[].aggregates[].spatial.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "admin_area"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/field",
        "key_path": "datasets[].aggregates[].allowed_filters[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/field",
        "key_path": "datasets[].entities[].aggregates[].allowed_filters[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/field",
        "key_path": "datasets[].entities[].api.allowed_filters[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/field",
        "key_path": "datasets[].tables[].aggregates[].allowed_filters[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/field",
        "key_path": "datasets[].tables[].api.allowed_filters[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops",
        "key_path": "datasets[].aggregates[].allowed_filters[].ops",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops",
        "key_path": "datasets[].entities[].aggregates[].allowed_filters[].ops",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops",
        "key_path": "datasets[].entities[].api.allowed_filters[].ops",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops",
        "key_path": "datasets[].tables[].aggregates[].allowed_filters[].ops",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops",
        "key_path": "datasets[].tables[].api.allowed_filters[].ops",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops/items",
        "key_path": "datasets[].aggregates[].allowed_filters[].ops[]",
        "path_kind": "array_item"
      },
      "purpose": "Filter operator opted into per field.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/FilterOp",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "eq",
            "in",
            "gte",
            "lte",
            "between"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FilterOp"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops/items",
        "key_path": "datasets[].entities[].aggregates[].allowed_filters[].ops[]",
        "path_kind": "array_item"
      },
      "purpose": "Filter operator opted into per field.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/FilterOp",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "eq",
            "in",
            "gte",
            "lte",
            "between"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FilterOp"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops/items",
        "key_path": "datasets[].entities[].api.allowed_filters[].ops[]",
        "path_kind": "array_item"
      },
      "purpose": "Filter operator opted into per field.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/FilterOp",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "eq",
            "in",
            "gte",
            "lte",
            "between"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FilterOp"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops/items",
        "key_path": "datasets[].tables[].aggregates[].allowed_filters[].ops[]",
        "path_kind": "array_item"
      },
      "purpose": "Filter operator opted into per field.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/FilterOp",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "eq",
            "in",
            "gte",
            "lte",
            "between"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FilterOp"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter/properties/ops/items",
        "key_path": "datasets[].tables[].api.allowed_filters[].ops[]",
        "path_kind": "array_item"
      },
      "purpose": "Filter operator opted into per field.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/FilterOp",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "eq",
            "in",
            "gte",
            "lte",
            "between"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FilterOp"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ApiKeyConfig/properties/fingerprint",
        "key_path": "auth.api_keys[].fingerprint",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CredentialFingerprintSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "provider",
              "name"
            ],
            [
              "provider",
              "path"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/CredentialFingerprintSchema"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ApiKeyConfig/properties/id",
        "key_path": "auth.api_keys[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ApiKeyConfig/properties/scopes",
        "key_path": "auth.api_keys[].scopes",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ApiKeyConfig/properties/scopes/items",
        "key_path": "auth.api_keys[].scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/claims",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims",
        "path_kind": "property"
      },
      "purpose": "Claims released on success. Non-empty; at least one `required`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/claims/items",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[]",
        "path_kind": "array_item"
      },
      "purpose": "A single released claim. Exactly one of `source_field` or `expression`\nmust be set: a claim is either a direct source-field projection or a\nCEL-computed value.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ReleaseClaimConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/description",
        "key_path": "datasets[].entities[].attribute_release_profiles[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/id",
        "key_path": "datasets[].entities[].attribute_release_profiles[].id",
        "path_kind": "property"
      },
      "purpose": "Profile identifier, lower-kebab/snake (`^[a-z][a-z0-9_-]*$`). Globally\nunique with `version`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/purpose",
        "key_path": "datasets[].entities[].attribute_release_profiles[].purpose",
        "path_kind": "property"
      },
      "purpose": "Data-purpose this profile is bound to. When the backing entity declares\n`governed_policy.permitted_purposes`, this must be a member.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/release_conditions",
        "key_path": "datasets[].entities[].attribute_release_profiles[].release_conditions",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "expression"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/release_scope",
        "key_path": "datasets[].entities[].attribute_release_profiles[].release_scope",
        "path_kind": "property"
      },
      "purpose": "Dataset-bound scope a caller must hold to invoke this release. The\nstable profile is exactly `<dataset_id>:identity_release`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/response",
        "key_path": "datasets[].entities[].attribute_release_profiles[].response",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ReleaseResponseConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseResponseConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/subject",
        "key_path": "datasets[].entities[].attribute_release_profiles[].subject",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ReleaseSubjectConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "source_field",
            "id_type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseSubjectConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/title",
        "key_path": "datasets[].entities[].attribute_release_profiles[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile/properties/version",
        "key_path": "datasets[].entities[].attribute_release_profiles[].version",
        "path_kind": "property"
      },
      "purpose": "Profile version. Globally unique with `id`; no silent \"latest\".",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/oneOf/0/properties/sink",
        "key_path": "audit.sink",
        "path_kind": "property"
      },
      "purpose": "Controls Relay audit event delivery, rotation, integrity chaining, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "file",
            "stdout",
            "syslog"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/oneOf/1/properties/path",
        "key_path": "audit.path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay audit event delivery, rotation, integrity chaining, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_audit_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/oneOf/1/properties/rotate",
        "key_path": "audit.rotate",
        "path_kind": "property"
      },
      "purpose": "In-process rotation for the `file` audit sink.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RotateConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "max_size_mb",
            "max_files"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RotateConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/properties/chain",
        "key_path": "audit.chain",
        "path_kind": "property"
      },
      "purpose": "Retains the compatibility switch in the authored contract; Relay audit envelopes remain integrity-chained regardless of this setting.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/properties/format",
        "key_path": "audit.format",
        "path_kind": "property"
      },
      "purpose": "Controls Relay audit event delivery, rotation, integrity chaining, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AuditFormat",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "jsonl"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditFormat"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/properties/hash_secret_env",
        "key_path": "audit.hash_secret_env",
        "path_kind": "property"
      },
      "purpose": "Name of the environment variable holding the per-deploy secret\nused to HMAC sensitive audit values (single-record primary keys,\nsensitive query parameters). Runtime startup fails closed when\nthis field is unset, empty, or points to a missing, empty, or\nweak secret. Direct middleware tests can opt into the explicit\nunkeyed dev-only hasher without using runtime config.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_audit_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[^=\\x00]*[^=\\x00\\x09-\\x0D\\x20\\x85\\u00A0\\u1680\\u2000-\\u200A\\u2028\\u2029\\u202F\\u205F\\u3000][^=\\x00]*$"
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/properties/include_health",
        "key_path": "audit.include_health",
        "path_kind": "property"
      },
      "purpose": "Include `/healthz` liveness probes in the audit stream. `/ready` is\nalways excluded because auditing it would advance the chain after its\nzero-backlog shipping check and self-invalidate the next probe.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig/properties/write_policy",
        "key_path": "audit.write_policy",
        "path_kind": "property"
      },
      "purpose": "Behavior when an audit record fails to write.\n\n`fail_closed` (default) fails the request with a stable error code so\nthat no request outcome is returned without a durable audit record.\n`availability_first` logs the failure and lets the request succeed for\ndeployments that explicitly accept best-effort audit durability.\nPer-route-family selection is out of scope; this is a single\ndeployment-wide policy.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AuditWritePolicySchema",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "availability_first",
            "fail_closed",
            "fail_closed_route_families"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditWritePolicySchema"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymMaterialCatalogConfig/items",
        "key_path": "consultation.audit_pseudonym_materials[]",
        "path_kind": "array_item"
      },
      "purpose": "One public epoch id bound to one secret source reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AuditPseudonymMaterialConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "key_id",
            "source"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymMaterialConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymMaterialConfig/properties/key_id",
        "key_path": "consultation.audit_pseudonym_materials[].key_id",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AuditPseudonymKeyIdSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z0-9][a-z0-9._-]{0,63}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymKeyIdSchema"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymMaterialConfig/properties/source",
        "key_path": "consultation.audit_pseudonym_materials[].source",
        "path_kind": "property"
      },
      "purpose": "Closed v1 set of audit-pseudonym secret source providers.\n\nThe configured name is a reference only. Secret values cannot be embedded\nin this model and are loaded exactly once during runtime compilation.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AuditPseudonymSecretSourceConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "provider",
            "name"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymSecretSourceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymSecretSourceConfig/oneOf/0/properties/name",
        "key_path": "consultation.audit_pseudonym_materials[].source.name",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a secret reference.\n\nDebug output is redacted even though the name is not itself key material,\npreventing configuration diagnostics from disclosing secret topology.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AuditPseudonymSecretEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymSecretEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymSecretSourceConfig/oneOf/0/properties/provider",
        "key_path": "consultation.audit_pseudonym_materials[].source.provider",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": "environment"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthConfig/properties/api_keys",
        "key_path": "auth.api_keys",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthConfig/properties/api_keys/items",
        "key_path": "auth.api_keys[]",
        "path_kind": "array_item"
      },
      "purpose": "One configured API key, identified by an id and a fingerprint reference.\nThe raw key never appears in config.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ApiKeyConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "fingerprint"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ApiKeyConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthConfig/properties/failure_throttle",
        "key_path": "auth.failure_throttle",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AuthFailureThrottleConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuthFailureThrottleConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthConfig/properties/mode",
        "key_path": "auth.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AuthMode",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "api_key",
            "oidc"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuthMode"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthConfig/properties/oidc",
        "key_path": "auth.oidc",
        "path_kind": "property"
      },
      "purpose": "OIDC / OAuth2 resource-server configuration. The relay validates\nincoming bearer JWTs against a configured external IdP. No tokens\nare minted here.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "issuer",
            "audiences"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthFailureThrottleConfig/properties/enabled",
        "key_path": "auth.failure_throttle.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthFailureThrottleConfig/properties/max_failures",
        "key_path": "auth.failure_throttle.max_failures",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/AuthFailureThrottleConfig/properties/window_seconds",
        "key_path": "auth.failure_throttle.window_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/authority_type",
        "key_path": "catalog.authority_type",
        "path_kind": "property"
      },
      "purpose": "BRegDCAT-AP: type IRI for the `foaf:Agent` publisher. When set, emits\n`dcterms:type` on the publisher node.\n\nBRegDCAT-AP 2.1.0 SHACL checks publisher type values against the ADMS\npublishertype scheme (`http://purl.org/adms/publishertype/...`).\nThe relay does not enforce a vocabulary: any IRI passes through.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_catalog_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public catalog metadata emitted by Relay discovery surfaces; this intent catalog records its contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public identifiers and non-routable placeholders; never copy country catalog values into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate discovery metadata changes with the Relay deployment and review the resulting public catalog before activation.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/base_url",
        "key_path": "catalog.base_url",
        "path_kind": "property"
      },
      "purpose": "Controls Relay catalog identity and public metadata exposed for governed discovery.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_catalog_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/default_spatial_coverage",
        "key_path": "catalog.default_spatial_coverage",
        "path_kind": "property"
      },
      "purpose": "BRegDCAT-AP: default `dcterms:spatial` IRI applied to datasets that\ndo not declare their own `spatial_coverage`. Typically an EU\nauthority country IRI under\n`http://publications.europa.eu/resource/authority/country/`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_catalog_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public catalog metadata emitted by Relay discovery surfaces; this intent catalog records its contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public identifiers and non-routable placeholders; never copy country catalog values into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate discovery metadata changes with the Relay deployment and review the resulting public catalog before activation.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/participant_id",
        "key_path": "catalog.participant_id",
        "path_kind": "property"
      },
      "purpose": "Identifies the participant in catalog output; when omitted, Relay derives the participant identifier from the reviewed catalog base URL.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_catalog_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public catalog metadata emitted by Relay discovery surfaces; this intent catalog records its contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public identifiers and non-routable placeholders; never copy country catalog values into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate discovery metadata changes with the Relay deployment and review the resulting public catalog before activation.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/publisher",
        "key_path": "catalog.publisher",
        "path_kind": "property"
      },
      "purpose": "Publishes the reviewed Relay catalog identity and descriptive metadata used for governed discovery.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_catalog_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public catalog metadata emitted by Relay discovery surfaces; this intent catalog records its contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public identifiers and non-routable placeholders; never copy country catalog values into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate discovery metadata changes with the Relay deployment and review the resulting public catalog before activation.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/publisher_iri",
        "key_path": "catalog.publisher_iri",
        "path_kind": "property"
      },
      "purpose": "BRegDCAT-AP: identifier IRI for the `foaf:Agent` publisher. Use a\ncontrolled-vocabulary corporate body IRI when publishing strict\nBRegDCAT-AP.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_catalog_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public catalog metadata emitted by Relay discovery surfaces; this intent catalog records its contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public identifiers and non-routable placeholders; never copy country catalog values into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate discovery metadata changes with the Relay deployment and review the resulting public catalog before activation.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig/properties/title",
        "key_path": "catalog.title",
        "path_kind": "property"
      },
      "purpose": "Publishes the reviewed Relay catalog identity and descriptive metadata used for governed discovery.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_catalog_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public catalog metadata emitted by Relay discovery surfaces; this intent catalog records its contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public identifiers and non-routable placeholders; never copy country catalog values into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate discovery metadata changes with the Relay deployment and review the resulting public catalog before activation.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConfigTrustConfig/properties/antirollback_state_path",
        "key_path": "config_trust.antirollback_state_path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_config_trust_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConfigTrustConfig/properties/break_glass_override_path",
        "key_path": "config_trust.break_glass_override_path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_config_trust_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConfigTrustConfig/properties/bundle_path",
        "key_path": "config_trust.bundle_path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_config_trust_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConfigTrustConfig/properties/trust_anchor_path",
        "key_path": "config_trust.trust_anchor_path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_config_trust_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/evidence",
        "key_path": "consultation.artifacts.evidence",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/evidence/items",
        "key_path": "consultation.artifacts.evidence[]",
        "path_kind": "array_item"
      },
      "purpose": "One bounded, hash-pinned integration evidence file.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationEvidenceArtifactConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "class",
            "path",
            "sha256"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationEvidenceArtifactConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/integration_packs",
        "key_path": "consultation.artifacts.integration_packs",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/integration_packs/items",
        "key_path": "consultation.artifacts.integration_packs[]",
        "path_kind": "array_item"
      },
      "purpose": "One hash-pinned public contract or reviewed integration pack.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationTypedArtifactReferenceConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "path",
            "hash",
            "sha256"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/private_bindings",
        "key_path": "consultation.artifacts.private_bindings",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/private_bindings/items",
        "key_path": "consultation.artifacts.private_bindings[]",
        "path_kind": "array_item"
      },
      "purpose": "One hash-pinned public contract or reviewed integration pack.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationTypedArtifactReferenceConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "path",
            "hash",
            "sha256"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/public_contracts",
        "key_path": "consultation.artifacts.public_contracts",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/public_contracts/items",
        "key_path": "consultation.artifacts.public_contracts[]",
        "path_kind": "array_item"
      },
      "purpose": "One hash-pinned public contract or reviewed integration pack.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationTypedArtifactReferenceConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "path",
            "hash",
            "sha256"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/rhai_scripts",
        "key_path": "consultation.artifacts.rhai_scripts",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactClosureConfig/properties/rhai_scripts/items",
        "key_path": "consultation.artifacts.rhai_scripts[]",
        "path_kind": "array_item"
      },
      "purpose": "One hash-pinned private binding or standalone Rhai script.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationArtifactReferenceConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "path",
            "sha256"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactReferenceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactReferenceConfig/properties/path",
        "key_path": "consultation.artifacts.rhai_scripts[].path",
        "path_kind": "property"
      },
      "purpose": "Normalized bundle-root-relative path.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationArtifactReferenceConfig/properties/sha256",
        "key_path": "consultation.artifacts.rhai_scripts[].sha256",
        "path_kind": "property"
      },
      "purpose": "Raw file hash recorded by Registry Config Bundle v1.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationConfig/properties/artifacts",
        "key_path": "consultation.artifacts",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "public_contracts",
            "integration_packs",
            "private_bindings",
            "evidence"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationConfig/properties/audit_pseudonym_materials",
        "key_path": "consultation.audit_pseudonym_materials",
        "path_kind": "property"
      },
      "purpose": "Bounded startup catalog of audit-pseudonym material references.\n\nThe 1..=32 bound and cross-entry uniqueness are enforced by config\nvalidation and repeated by the material provider before loading secrets.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/AuditPseudonymMaterialCatalogConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditPseudonymMaterialCatalogConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationConfig/properties/authorized_workload",
        "key_path": "consultation.authorized_workload",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationWorkloadConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "audience",
            "client_claim_selector",
            "client_value",
            "principal_id"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationWorkloadConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationConfig/properties/source_credentials",
        "key_path": "consultation.source_credentials",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "local_reference": "#/$defs/ConsultationSourceCredentialCatalogConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialCatalogConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationConfig/properties/state_plane",
        "key_path": "consultation.state_plane",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationStatePlaneConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "database_url_env",
            "chain_key_epoch_id",
            "serving_fence_lock_key",
            "audit_pseudonym_keyring_lock_key"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationStatePlaneConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationEvidenceArtifactConfig/properties/class",
        "key_path": "consultation.artifacts.evidence[].class",
        "path_kind": "property"
      },
      "purpose": "Closed evidence classes understood by consultation source-plan v1.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationEvidenceClassConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "conformance",
            "negative_security",
            "minimization"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationEvidenceClassConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationEvidenceArtifactConfig/properties/path",
        "key_path": "consultation.artifacts.evidence[].path",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationEvidenceArtifactConfig/properties/sha256",
        "key_path": "consultation.artifacts.evidence[].sha256",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialCatalogConfig/items",
        "key_path": "consultation.source_credentials[]",
        "path_kind": "array_item"
      },
      "purpose": "Closed V1 source-credential provider configuration.\n\nEnvironment names are opaque references and are redacted from `Debug`.\nThere is deliberately no field capable of carrying an embedded username,\npassword, bearer token, or provider-specific extension.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConsultationSourceCredentialConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "type",
              "ref",
              "generation",
              "client_id_env",
              "client_secret_env"
            ],
            [
              "type",
              "ref",
              "generation",
              "token_env"
            ],
            [
              "type",
              "ref",
              "generation",
              "username_env",
              "password_env"
            ],
            [
              "type",
              "ref",
              "generation",
              "value_env"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/0/properties/generation",
        "key_path": "consultation.source_credentials[].generation",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/0/properties/password_env",
        "key_path": "consultation.source_credentials[].password_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a credential reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationCredentialEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationCredentialEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/0/properties/ref",
        "key_path": "consultation.source_credentials[].ref",
        "path_kind": "property"
      },
      "purpose": "Exact private-binding credential reference grammar.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationSourceCredentialReference",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9._-]{0,95}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialReference"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/0/properties/type",
        "key_path": "consultation.source_credentials[].type",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "api_key_header",
            "api_key_query",
            "basic",
            "oauth_client_credentials",
            "static_bearer"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/0/properties/username_env",
        "key_path": "consultation.source_credentials[].username_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a credential reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationCredentialEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationCredentialEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/1/properties/token_env",
        "key_path": "consultation.source_credentials[].token_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a credential reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationCredentialEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationCredentialEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/2/properties/value_env",
        "key_path": "consultation.source_credentials[].value_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a credential reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationCredentialEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationCredentialEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/4/properties/client_id_env",
        "key_path": "consultation.source_credentials[].client_id_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a credential reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationCredentialEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationCredentialEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationSourceCredentialConfig/oneOf/4/properties/client_secret_env",
        "key_path": "consultation.source_credentials[].client_secret_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name used only as a credential reference.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationCredentialEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationCredentialEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationStatePlaneConfig/properties/audit_pseudonym_keyring_lock_key",
        "key_path": "consultation.state_plane.audit_pseudonym_keyring_lock_key",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int64"
        },
        {
          "keyword": "maximum",
          "value": 9223372036854775807
        },
        {
          "keyword": "minimum",
          "value": -9223372036854775808
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationStatePlaneConfig/properties/chain_key_epoch_id",
        "key_path": "consultation.state_plane.chain_key_epoch_id",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationStatePlaneConfig/properties/database_url_env",
        "key_path": "consultation.state_plane.database_url_env",
        "path_kind": "property"
      },
      "purpose": "Portable environment-variable name that resolves the state-plane URL.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationDatabaseUrlEnvironmentName",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]{0,127}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationDatabaseUrlEnvironmentName"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationStatePlaneConfig/properties/root_certificate_path",
        "key_path": "consultation.state_plane.root_certificate_path",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationStatePlaneConfig/properties/serving_fence_lock_key",
        "key_path": "consultation.state_plane.serving_fence_lock_key",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int64"
        },
        {
          "keyword": "maximum",
          "value": 9223372036854775807
        },
        {
          "keyword": "minimum",
          "value": -9223372036854775808
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/hash",
        "key_path": "consultation.artifacts.integration_packs[].hash",
        "path_kind": "property"
      },
      "purpose": "Domain-separated typed artifact hash consumed by the source-plan compiler.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/hash",
        "key_path": "consultation.artifacts.private_bindings[].hash",
        "path_kind": "property"
      },
      "purpose": "Domain-separated typed artifact hash consumed by the source-plan compiler.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/hash",
        "key_path": "consultation.artifacts.public_contracts[].hash",
        "path_kind": "property"
      },
      "purpose": "Domain-separated typed artifact hash consumed by the source-plan compiler.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/path",
        "key_path": "consultation.artifacts.integration_packs[].path",
        "path_kind": "property"
      },
      "purpose": "Normalized bundle-root-relative path.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/path",
        "key_path": "consultation.artifacts.private_bindings[].path",
        "path_kind": "property"
      },
      "purpose": "Normalized bundle-root-relative path.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/path",
        "key_path": "consultation.artifacts.public_contracts[].path",
        "path_kind": "property"
      },
      "purpose": "Normalized bundle-root-relative path.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/sha256",
        "key_path": "consultation.artifacts.integration_packs[].sha256",
        "path_kind": "property"
      },
      "purpose": "Raw file hash recorded by Registry Config Bundle v1.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/sha256",
        "key_path": "consultation.artifacts.private_bindings[].sha256",
        "path_kind": "property"
      },
      "purpose": "Raw file hash recorded by Registry Config Bundle v1.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationTypedArtifactReferenceConfig/properties/sha256",
        "key_path": "consultation.artifacts.public_contracts[].sha256",
        "path_kind": "property"
      },
      "purpose": "Raw file hash recorded by Registry Config Bundle v1.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^sha256:[0-9a-f]{64}$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationWorkloadConfig/properties/audience",
        "key_path": "consultation.authorized_workload.audience",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationWorkloadConfig/properties/client_claim_selector",
        "key_path": "consultation.authorized_workload.client_claim_selector",
        "path_kind": "property"
      },
      "purpose": "Closed set of verified OAuth claims that may identify Registry Notary.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ConsultationClientClaimSelectorConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "azp",
            "client_id"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationClientClaimSelectorConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationWorkloadConfig/properties/client_value",
        "key_path": "consultation.authorized_workload.client_value",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ConsultationWorkloadConfig/properties/principal_id",
        "key_path": "consultation.authorized_workload.principal_id",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CorsConfig/properties/allowed_origins",
        "key_path": "server.cors.allowed_origins",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CorsConfig/properties/allowed_origins/items",
        "key_path": "server.cors.allowed_origins[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CredentialFingerprintSchema/oneOf/0/properties/name",
        "key_path": "auth.api_keys[].fingerprint.name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RuntimeEnvironmentNameSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[^=\\x00]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RuntimeEnvironmentNameSchema"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CredentialFingerprintSchema/oneOf/0/properties/provider",
        "key_path": "auth.api_keys[].fingerprint.provider",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "env",
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CredentialFingerprintSchema/oneOf/1/properties/path",
        "key_path": "auth.api_keys[].fingerprint.path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CsvFormatConfig/properties/delimiter",
        "key_path": "datasets[].tables[].source.format.csv.delimiter",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint8"
        },
        {
          "keyword": "maximum",
          "value": 255
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CsvFormatConfig/properties/header_row",
        "key_path": "datasets[].tables[].source.format.csv.header_row",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/CsvFormatConfig/properties/quote",
        "key_path": "datasets[].tables[].source.format.csv.quote",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint8"
        },
        {
          "keyword": "maximum",
          "value": 255
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/access_rights",
        "key_path": "datasets[].access_rights",
        "path_kind": "property"
      },
      "purpose": "Access rights classification, mirrors DCAT-AP `dcterms:accessRights`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/AccessRights",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "public",
            "restricted",
            "non_public"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AccessRights"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/aggregates",
        "key_path": "datasets[].aggregates",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/aggregates/items",
        "key_path": "datasets[].aggregates[]",
        "path_kind": "array_item"
      },
      "purpose": "Aggregate declaration: group-by columns, measures, disclosure\ncontrol.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "description",
            "disclosure_control"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/applicable_legislation",
        "key_path": "datasets[].applicable_legislation",
        "path_kind": "property"
      },
      "purpose": "DCAT-AP `dcatap:applicableLegislation` IRIs. This is evidence\npublished for standard consumers, not an application-specific\nauthorization or source-of-truth verdict.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/applicable_legislation/items",
        "key_path": "datasets[].applicable_legislation[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/conforms_to",
        "key_path": "datasets[].conforms_to",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/conforms_to/items",
        "key_path": "datasets[].conforms_to[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/defaults",
        "key_path": "datasets[].defaults",
        "path_kind": "property"
      },
      "purpose": "Optional table defaults for reducing repetition within one dataset.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DatasetDefaultsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DatasetDefaultsConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/description",
        "key_path": "datasets[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/entities",
        "key_path": "datasets[].entities",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/entities/items",
        "key_path": "datasets[].entities[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EntityConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "table",
            "access",
            "api"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/id",
        "key_path": "datasets[].id",
        "path_kind": "property"
      },
      "purpose": "Dataset identifier. Lower-snake, starts with a letter.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DatasetId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DatasetId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/owner",
        "key_path": "datasets[].owner",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/public_services",
        "key_path": "datasets[].public_services",
        "path_kind": "property"
      },
      "purpose": "CPSV public services that produce this dataset. Registry Relay emits\nthem as standard `cpsv:PublicService` nodes; consumers decide how to\ninterpret that evidence.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/public_services/items",
        "key_path": "datasets[].public_services[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/PublicServiceConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "title"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/PublicServiceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/sensitivity",
        "key_path": "datasets[].sensitivity",
        "path_kind": "property"
      },
      "purpose": "Sensitivity classification. Operator-defined values cover common\npersonal and public dataset classifications in V1.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/Sensitivity",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "public",
            "internal",
            "personal",
            "confidential",
            "secret"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/Sensitivity"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/spatial_coverage",
        "key_path": "datasets[].spatial_coverage",
        "path_kind": "property"
      },
      "purpose": "BRegDCAT-AP: `dct:spatial` IRI for this dataset. Overrides the\ncatalog-level `default_spatial_coverage` when set.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/status",
        "key_path": "datasets[].status",
        "path_kind": "property"
      },
      "purpose": "Publishes the dataset lifecycle status; when omitted, Relay emits its weakest lifecycle claim instead of inferring a stronger status.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "under_development",
            "completed",
            "deprecated",
            "withdrawn"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/tables",
        "key_path": "datasets[].tables",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/tables/items",
        "key_path": "datasets[].tables[]",
        "path_kind": "array_item"
      },
      "purpose": "One private storage table under a dataset.\n\nThe public API should not expose these ids. Entity config maps one\nresource into one domain resource, with optional field renaming and\nrelationship declarations.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ResourceConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "source",
            "schema"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/title",
        "key_path": "datasets[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig/properties/update_frequency",
        "key_path": "datasets[].update_frequency",
        "path_kind": "property"
      },
      "purpose": "Update cadence; mirrors DCAT-AP `dcterms:accrualPeriodicity`. The\nV1 set is the codes used by the example plus the common alternates.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/UpdateFrequency",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "continuous",
            "daily",
            "weekly",
            "termly",
            "monthly",
            "quarterly",
            "annual",
            "irregular",
            "as_needed",
            "unknown"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/UpdateFrequency"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetDefaultsConfig/properties/materialization",
        "key_path": "datasets[].defaults.materialization",
        "path_kind": "property"
      },
      "purpose": "How a configured private table is registered for query planning.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "snapshot"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DatasetDefaultsConfig/properties/refresh",
        "key_path": "datasets[].defaults.refresh",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "mode",
              "interval"
            ],
            [
              "mode"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentConfig/properties/evidence",
        "key_path": "deployment.evidence",
        "path_kind": "property"
      },
      "purpose": "Declares Relay deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DeploymentEvidenceConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentEvidenceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentConfig/properties/profile",
        "key_path": "deployment.profile",
        "path_kind": "property"
      },
      "purpose": "Declares Relay deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "local",
            "hosted_lab",
            "production",
            "evidence_grade"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentConfig/properties/waivers",
        "key_path": "deployment.waivers",
        "path_kind": "property"
      },
      "purpose": "Per-deployment waivers. Each names one finding id, a required operator\nreference, an optional summary, and a mandatory expiry date. Expired\nwaivers stop suppressing their finding and raise\n`deployment.waiver_expired`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentConfig/properties/waivers/items",
        "key_path": "deployment.waivers[]",
        "path_kind": "array_item"
      },
      "purpose": "One declared waiver. `expires` is an ISO 8601 `YYYY-MM-DD` date; format is\nvalidated at load time. The reference and optional summary are validated by\nthe shared operations contract before either can reach posture or logs.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DeploymentWaiverConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "finding",
            "reference",
            "expires"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/api_key_rotation",
        "key_path": "deployment.evidence.api_key_rotation",
        "path_kind": "property"
      },
      "purpose": "Operator asserts an API-key rotation process is in place.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/audit_ack_cursor_path",
        "key_path": "deployment.evidence.audit_ack_cursor_path",
        "path_kind": "property"
      },
      "purpose": "Optional path to a `registry.audit.ack_cursor.v1` file maintained by\nwhatever ships audit events off-host. When set, the runtime reads it to\nobserve shipping freshness and surfaces it as posture shipping health;\nabsent, shipping health stays `unverified` and only the declared\nshipping target is reported.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/audit_ack_max_age_secs",
        "key_path": "deployment.evidence.audit_ack_max_age_secs",
        "path_kind": "property"
      },
      "purpose": "Optional freshness window in seconds for the ack cursor's `acked_at`\ntimestamp. Defaults to `DEFAULT_AUDIT_ACK_MAX_AGE` (900) when unset. A\nwindow without `audit_ack_cursor_path` is rejected at load, since a\nfreshness window is meaningless without a cursor to observe.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/audit_offhost_shipping",
        "key_path": "deployment.evidence.audit_offhost_shipping",
        "path_kind": "property"
      },
      "purpose": "Operator asserts audit records are shipped off-host (for example to a\nlog collector or SIEM) rather than relying solely on local retention.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/ingress_rate_limit",
        "key_path": "deployment.evidence.ingress_rate_limit",
        "path_kind": "property"
      },
      "purpose": "Operator asserts ingress rate limiting is enforced (for example by a\ngateway or reverse proxy in front of the relay).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/expires",
        "key_path": "deployment.waivers[].expires",
        "path_kind": "property"
      },
      "purpose": "Declares Relay deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/finding",
        "key_path": "deployment.waivers[].finding",
        "path_kind": "property"
      },
      "purpose": "Declares Relay deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/reference",
        "key_path": "deployment.waivers[].reference",
        "path_kind": "property"
      },
      "purpose": "Declares Relay deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DeploymentWaiverReference",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!.*\\.\\.)[A-Za-z0-9._:-]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverReference"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/summary",
        "key_path": "deployment.waivers[].summary",
        "path_kind": "property"
      },
      "purpose": "Structurally valid deployment-waiver summary. Contextual authorization-value and private-key marker exclusions require semantic producer validation.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DeploymentWaiverSummary",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentWaiverSummary"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/method",
        "key_path": "datasets[].aggregates[].disclosure_control.method",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/method",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control.method",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/method",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control.method",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/method/items",
        "key_path": "datasets[].aggregates[].disclosure_control.method[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/method/items",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control.method[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/method/items",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control.method[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/min_cell_size",
        "key_path": "datasets[].aggregates[].disclosure_control.min_cell_size",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/min_cell_size",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control.min_cell_size",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/min_cell_size",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control.min_cell_size",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/min_group_size",
        "key_path": "datasets[].aggregates[].disclosure_control.min_group_size",
        "path_kind": "property"
      },
      "purpose": "Optionally overrides the effective disclosure threshold for grouped results; when omitted, Relay uses the configured cell threshold.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/min_group_size",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control.min_group_size",
        "path_kind": "property"
      },
      "purpose": "Optionally overrides the effective disclosure threshold for grouped results; when omitted, Relay uses the configured cell threshold.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/min_group_size",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control.min_group_size",
        "path_kind": "property"
      },
      "purpose": "Optionally overrides the effective disclosure threshold for grouped results; when omitted, Relay uses the configured cell threshold.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/report_suppressed_rows",
        "key_path": "datasets[].aggregates[].disclosure_control.report_suppressed_rows",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/report_suppressed_rows",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control.report_suppressed_rows",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/report_suppressed_rows",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control.report_suppressed_rows",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/suppression",
        "key_path": "datasets[].aggregates[].disclosure_control.suppression",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/Suppression",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "mask",
            "null",
            "omit"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/Suppression"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/suppression",
        "key_path": "datasets[].entities[].aggregates[].disclosure_control.suppression",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/Suppression",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "mask",
            "null",
            "omit"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/Suppression"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/DisclosureControlConfig/properties/suppression",
        "key_path": "datasets[].tables[].aggregates[].disclosure_control.suppression",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/Suppression",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "mask",
            "null",
            "omit"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/Suppression"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EcosystemBindingSelectorConfig/properties/id",
        "key_path": "metadata.ecosystem_binding.id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay metadata publication and registry-description behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_metadata_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EcosystemBindingSelectorConfig/properties/version",
        "key_path": "metadata.ecosystem_binding.version",
        "path_kind": "property"
      },
      "purpose": "Controls Relay metadata publication and registry-description behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_metadata_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityAccessConfig/properties/aggregate_scope",
        "key_path": "datasets[].entities[].access.aggregate_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityAccessConfig/properties/evidence_verification_scope",
        "key_path": "datasets[].entities[].access.evidence_verification_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityAccessConfig/properties/metadata_scope",
        "key_path": "datasets[].entities[].access.metadata_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityAccessConfig/properties/read_scope",
        "key_path": "datasets[].entities[].access.read_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/allowed_expansions",
        "key_path": "datasets[].entities[].api.allowed_expansions",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/allowed_expansions/items",
        "key_path": "datasets[].entities[].api.allowed_expansions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/allowed_filters",
        "key_path": "datasets[].entities[].api.allowed_filters",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/allowed_filters/items",
        "key_path": "datasets[].entities[].api.allowed_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "A single allowed filter: field name + permitted operators.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AllowedFilter",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field",
            "ops"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/default_limit",
        "key_path": "datasets[].entities[].api.default_limit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/governed_policy",
        "key_path": "datasets[].entities[].api.governed_policy",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/max_limit",
        "key_path": "datasets[].entities[].api.max_limit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/require_purpose_header",
        "key_path": "datasets[].entities[].api.require_purpose_header",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/required_filter_bindings",
        "key_path": "datasets[].entities[].api.required_filter_bindings",
        "path_kind": "property"
      },
      "purpose": "Principal-derived bindings that both satisfy the required filter gate\nand are applied to the query.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/required_filter_bindings/items",
        "key_path": "datasets[].entities[].api.required_filter_bindings[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/required_filters",
        "key_path": "datasets[].entities[].api.required_filters",
        "path_kind": "property"
      },
      "purpose": "Alternative fields that can satisfy the row-scope gate. A\nprincipal-bound equality filter on any listed field is sufficient, so\nlist multiple fields only when each is an acceptable boundary.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig/properties/required_filters/items",
        "key_path": "datasets[].entities[].api.required_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/access",
        "key_path": "datasets[].entities[].access",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EntityAccessConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "metadata_scope",
            "aggregate_scope",
            "read_scope"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/EntityAccessConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/aggregates",
        "key_path": "datasets[].entities[].aggregates",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/aggregates/items",
        "key_path": "datasets[].entities[].aggregates[]",
        "path_kind": "array_item"
      },
      "purpose": "Aggregate declaration: group-by columns, measures, disclosure\ncontrol.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "description",
            "disclosure_control"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/api",
        "key_path": "datasets[].entities[].api",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EntityApiConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "default_limit",
            "max_limit"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/EntityApiConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/attribute_release_profiles",
        "key_path": "datasets[].entities[].attribute_release_profiles",
        "path_kind": "property"
      },
      "purpose": "Governed identity attribute-release profiles attached to this entity.\nEach profile resolves exactly one subject and returns only the\nconfigured, minimised claims. Empty by default (feature opt-in).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/attribute_release_profiles/items",
        "key_path": "datasets[].entities[].attribute_release_profiles[]",
        "path_kind": "array_item"
      },
      "purpose": "A governed identity attribute-release profile. A profile is a\nprojection-limited, exactly-one-subject lookup that maps a configured set of\nsource fields (or CEL-computed expressions) into a minimised\nOIDC/UserInfo-style claim bundle. Every profile is purpose-bound and requires\na matching `data-purpose` at resolve time. Identified globally by the\n`(id, version)` pair; both are required path segments at resolve time.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AttributeReleaseProfile",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "version",
            "purpose",
            "release_scope",
            "subject",
            "claims"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AttributeReleaseProfile"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/concept_uri",
        "key_path": "datasets[].entities[].concept_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/description",
        "key_path": "datasets[].entities[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/fields",
        "key_path": "datasets[].entities[].fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/fields/items",
        "key_path": "datasets[].entities[].fields[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EntityFieldConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/name",
        "key_path": "datasets[].entities[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/relationships",
        "key_path": "datasets[].entities[].relationships",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/relationships/items",
        "key_path": "datasets[].entities[].relationships[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EntityRelationshipConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "kind",
            "target",
            "foreign_key"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/EntityRelationshipConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/spatial",
        "key_path": "datasets[].entities[].spatial",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "geometry"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/table",
        "key_path": "datasets[].entities[].table",
        "path_kind": "property"
      },
      "purpose": "Resource identifier within a dataset.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ResourceId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ResourceId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityConfig/properties/title",
        "key_path": "datasets[].entities[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/codelist",
        "key_path": "datasets[].entities[].fields[].codelist",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/concept_uri",
        "key_path": "datasets[].entities[].fields[].concept_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/from",
        "key_path": "datasets[].entities[].fields[].from",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/language",
        "key_path": "datasets[].entities[].fields[].language",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/name",
        "key_path": "datasets[].entities[].fields[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/sensitive",
        "key_path": "datasets[].entities[].fields[].sensitive",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityFieldConfig/properties/unit",
        "key_path": "datasets[].entities[].fields[].unit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityRelationshipConfig/properties/concept_uri",
        "key_path": "datasets[].entities[].relationships[].concept_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityRelationshipConfig/properties/foreign_key",
        "key_path": "datasets[].entities[].relationships[].foreign_key",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityRelationshipConfig/properties/kind",
        "key_path": "datasets[].entities[].relationships[].kind",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RelationshipKind",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "belongs_to",
            "has_many",
            "has_one"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RelationshipKind"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityRelationshipConfig/properties/name",
        "key_path": "datasets[].entities[].relationships[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntityRelationshipConfig/properties/target",
        "key_path": "datasets[].entities[].relationships[].target",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/bbox_fields",
        "key_path": "datasets[].entities[].spatial.bbox_fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "min_x",
            "min_y",
            "max_x",
            "max_y"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/collection_id",
        "key_path": "datasets[].entities[].spatial.collection_id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/datetime_field",
        "key_path": "datasets[].entities[].spatial.datetime_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/description",
        "key_path": "datasets[].entities[].spatial.description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/geometry",
        "key_path": "datasets[].entities[].spatial.geometry",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SpatialGeometryConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "kind",
              "field",
              "crs"
            ],
            [
              "kind",
              "longitude_field",
              "latitude_field",
              "crs"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/SpatialGeometryConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/max_bbox_degrees",
        "key_path": "datasets[].entities[].spatial.max_bbox_degrees",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "number"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "double"
        },
        {
          "keyword": "type",
          "value": "number"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/max_geometry_vertices",
        "key_path": "datasets[].entities[].spatial.max_geometry_vertices",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/EntitySpatialConfig/properties/title",
        "key_path": "datasets[].entities[].spatial.title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/codelist",
        "key_path": "datasets[].tables[].schema.fields[].codelist",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/concept_uri",
        "key_path": "datasets[].tables[].schema.fields[].concept_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/language",
        "key_path": "datasets[].tables[].schema.fields[].language",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/name",
        "key_path": "datasets[].tables[].schema.fields[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/nullable",
        "key_path": "datasets[].tables[].schema.fields[].nullable",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/sensitive",
        "key_path": "datasets[].tables[].schema.fields[].sensitive",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/type",
        "key_path": "datasets[].tables[].schema.fields[].type",
        "path_kind": "property"
      },
      "purpose": "Physical type of a column. The set is fixed in V1; semantic types\nare carried via `concept_uri`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/FieldType",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "string",
            "number",
            "integer",
            "boolean",
            "date",
            "timestamp"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FieldType"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig/properties/unit",
        "key_path": "datasets[].tables[].schema.fields[].unit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/allowed_assurance",
        "key_path": "datasets[].entities[].api.governed_policy.allowed_assurance",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/allowed_assurance/items",
        "key_path": "datasets[].entities[].api.governed_policy.allowed_assurance[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/max_source_age_seconds",
        "key_path": "datasets[].entities[].api.governed_policy.max_source_age_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/minimum_assurance",
        "key_path": "datasets[].entities[].api.governed_policy.minimum_assurance",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/permitted_jurisdictions",
        "key_path": "datasets[].entities[].api.governed_policy.permitted_jurisdictions",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/permitted_jurisdictions/items",
        "key_path": "datasets[].entities[].api.governed_policy.permitted_jurisdictions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/permitted_purposes",
        "key_path": "datasets[].entities[].api.governed_policy.permitted_purposes",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/permitted_purposes/items",
        "key_path": "datasets[].entities[].api.governed_policy.permitted_purposes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/redaction_fields",
        "key_path": "datasets[].entities[].api.governed_policy.redaction_fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/redaction_fields/items",
        "key_path": "datasets[].entities[].api.governed_policy.redaction_fields[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/require_consent",
        "key_path": "datasets[].entities[].api.governed_policy.require_consent",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/require_legal_basis",
        "key_path": "datasets[].entities[].api.governed_policy.require_legal_basis",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedPolicyConfig/properties/trusted_context",
        "key_path": "datasets[].entities[].api.governed_policy.trusted_context",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/GovernedTrustedContextConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/GovernedTrustedContextConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedTrustedContextConfig/properties/asserted_assurance",
        "key_path": "datasets[].entities[].api.governed_policy.trusted_context.asserted_assurance",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedTrustedContextConfig/properties/consent_ref",
        "key_path": "datasets[].entities[].api.governed_policy.trusted_context.consent_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedTrustedContextConfig/properties/jurisdiction",
        "key_path": "datasets[].entities[].api.governed_policy.trusted_context.jurisdiction",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedTrustedContextConfig/properties/legal_basis_ref",
        "key_path": "datasets[].entities[].api.governed_policy.trusted_context.legal_basis_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/GovernedTrustedContextConfig/properties/source_observed_age_seconds",
        "key_path": "datasets[].entities[].api.governed_policy.trusted_context.source_observed_age_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/InstanceConfig/properties/environment",
        "key_path": "instance.environment",
        "path_kind": "property"
      },
      "purpose": "Identifies the public Relay instance labels surfaced by posture and operations tooling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_instance_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public instance labels surfaced by Relay posture and operations tooling; this intent catalog records their contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public labels; never copy a country deployment identity into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate changes to public instance identity with the Relay deployment and its operational inventory.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/InstanceConfig/properties/id",
        "key_path": "instance.id",
        "path_kind": "property"
      },
      "purpose": "Identifies the public Relay instance labels surfaced by posture and operations tooling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_instance_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public instance labels surfaced by Relay posture and operations tooling; this intent catalog records their contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public labels; never copy a country deployment identity into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate changes to public instance identity with the Relay deployment and its operational inventory.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/InstanceConfig/properties/jurisdiction",
        "key_path": "instance.jurisdiction",
        "path_kind": "property"
      },
      "purpose": "Identifies the public Relay instance labels surfaced by posture and operations tooling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_instance_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public instance labels surfaced by Relay posture and operations tooling; this intent catalog records their contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public labels; never copy a country deployment identity into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate changes to public instance identity with the Relay deployment and its operational inventory.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/InstanceConfig/properties/owner",
        "key_path": "instance.owner",
        "path_kind": "property"
      },
      "purpose": "Identifies the public Relay instance labels surfaced by posture and operations tooling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_instance_public",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "Public instance labels surfaced by Relay posture and operations tooling; this intent catalog records their contract without loading deployment values.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "public",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic public labels; never copy a country deployment identity into generated reference documentation.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate changes to public instance identity with the Relay deployment and its operational inventory.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/MetadataConfig/properties/ecosystem_binding",
        "key_path": "metadata.ecosystem_binding",
        "path_kind": "property"
      },
      "purpose": "Controls Relay metadata publication and registry-description behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_metadata_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/MetadataConfig/properties/source",
        "key_path": "metadata.source",
        "path_kind": "property"
      },
      "purpose": "Controls Relay metadata publication and registry-description behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_metadata_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/MetadataSourceConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "path"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/MetadataSourceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/MetadataSourceConfig/properties/digest",
        "key_path": "metadata.source.digest",
        "path_kind": "property"
      },
      "purpose": "Controls Relay metadata publication and registry-description behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_metadata_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/MetadataSourceConfig/properties/path",
        "key_path": "metadata.source.path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay metadata publication and registry-description behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_metadata_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allow_dev_insecure_fetch_urls",
        "key_path": "auth.oidc.allow_dev_insecure_fetch_urls",
        "path_kind": "property"
      },
      "purpose": "Development-only escape hatch that permits loopback HTTP issuer,\ndiscovery, and JWKS URLs. Private non-loopback networks and cloud\nmetadata endpoints remain denied by the platform fetch policy.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allowed_algorithms",
        "key_path": "auth.oidc.allowed_algorithms",
        "path_kind": "property"
      },
      "purpose": "Signature algorithms accepted by the verifier. Defaults to\nRS256, ES256, EdDSA. HS\\* and `none` are intentionally absent\nfrom [`OidcAlgorithm`].",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allowed_algorithms/items",
        "key_path": "auth.oidc.allowed_algorithms[]",
        "path_kind": "array_item"
      },
      "purpose": "JWS signature algorithms accepted by the OIDC verifier. Symmetric\nalgorithms (`HS*`) and `none` are intentionally absent: shared-secret\nJWTs are unsafe between a resource server and an IdP, and `none`\ndisables verification entirely.\n\nYAML values are the canonical JWA `alg` strings (`RS256`, `ES256`,\n`EdDSA`), case-sensitive.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/OidcAlgorithm",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "RS256",
            "ES256",
            "EdDSA"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/OidcAlgorithm"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allowed_clients",
        "key_path": "auth.oidc.allowed_clients",
        "path_kind": "property"
      },
      "purpose": "Optional allowlist of client identifiers, matched against the\ntoken's `azp` (preferred) or `client_id` claim. Empty list\nmeans any client is accepted.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allowed_clients/items",
        "key_path": "auth.oidc.allowed_clients[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allowed_token_types",
        "key_path": "auth.oidc.allowed_token_types",
        "path_kind": "property"
      },
      "purpose": "Accepted `typ` JOSE header values. Defaults to `JWT` and\n`at+jwt` (RFC 9068). ID tokens (`id+jwt`) are not access tokens\nand are rejected by default. Tokens without `typ` are rejected by\nthe shared verifier.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/allowed_token_types/items",
        "key_path": "auth.oidc.allowed_token_types[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/audiences",
        "key_path": "auth.oidc.audiences",
        "path_kind": "property"
      },
      "purpose": "One or more accepted `aud` values. Tokens with no `aud`, or\nwhose `aud` does not intersect this list, are rejected.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/audiences/items",
        "key_path": "auth.oidc.audiences[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/discovery_url",
        "key_path": "auth.oidc.discovery_url",
        "path_kind": "property"
      },
      "purpose": "OIDC discovery document URL\n(`.well-known/openid-configuration`). The JWKS URL is resolved\nfrom `jwks_uri` in the discovered document.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/issuer",
        "key_path": "auth.oidc.issuer",
        "path_kind": "property"
      },
      "purpose": "Issuer URL. Compared verbatim against the JWT `iss` claim.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/jwks_cache_ttl",
        "key_path": "auth.oidc.jwks_cache_ttl",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/jwks_url",
        "key_path": "auth.oidc.jwks_url",
        "path_kind": "property"
      },
      "purpose": "JWKS endpoint. Either this or `discovery_url` must be set.\n`discovery_url` takes precedence: when both are configured the\nvalidator rejects the document.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/leeway",
        "key_path": "auth.oidc.leeway",
        "path_kind": "property"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/scope_claim",
        "key_path": "auth.oidc.scope_claim",
        "path_kind": "property"
      },
      "purpose": "JWT claim whose value carries scopes. Defaults to `scope`, the\nRFC 8693 / RFC 9068 space-separated form. Some IdPs use `scp`\nor `permissions`; the value may be a string, an array of strings,\nor an object keyed by scope name.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/scope_map",
        "key_path": "auth.oidc.scope_map",
        "path_kind": "property"
      },
      "purpose": "Optional rename map: `external_scope -> internal_scope`. Applied\nafter parsing the scope claim, before scope-based access checks\nrun. Useful for adapting IdP role names (`role:foo`) to the\nrelay's `<dataset_id>:<level>` shape.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/scope_map/additionalProperties",
        "key_path": "auth.oidc.scope_map.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key is an external token scope and each value is the bounded Relay scope mapping granted for that exact token scope.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_oidc_scope_map_open_map",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/scope_object_required_keys",
        "key_path": "auth.oidc.scope_object_required_keys",
        "path_kind": "property"
      },
      "purpose": "Keys that must be present inside object-valued role claim values\nbefore the role key is treated as an active scope. Object-valued\nclaims grant no scopes when this list is empty.\nThis is useful for IdPs such as Zitadel where role values are\nkeyed by organization id.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/OidcConfig/properties/scope_object_required_keys/items",
        "key_path": "auth.oidc.scope_object_required_keys[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay caller authentication, authorization scopes, token verification, and abuse throttling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_auth_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/PostgresTableConfig/properties/name",
        "key_path": "datasets[].tables[].source.table.name",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/PostgresTableConfig/properties/schema",
        "key_path": "datasets[].tables[].source.table.schema",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/PublicServiceConfig/properties/description",
        "key_path": "datasets[].public_services[].description",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/PublicServiceConfig/properties/id",
        "key_path": "datasets[].public_services[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/PublicServiceConfig/properties/title",
        "key_path": "datasets[].public_services[].title",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RefreshConfig/oneOf/0/properties/interval",
        "key_path": "datasets[].defaults.refresh.interval",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RefreshConfig/oneOf/0/properties/interval",
        "key_path": "datasets[].tables[].refresh.interval",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "conditional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RefreshConfig/oneOf/0/properties/mode",
        "key_path": "datasets[].defaults.refresh.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "interval",
            "manual",
            "mtime"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RefreshConfig/oneOf/0/properties/mode",
        "key_path": "datasets[].tables[].refresh.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "interval",
            "manual",
            "mtime"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/expression",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].expression",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "cel"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/format",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].format",
        "path_kind": "property"
      },
      "purpose": "Optional value format hint.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/locale",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].locale",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/name",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].name",
        "path_kind": "property"
      },
      "purpose": "Released claim name (lower-snake).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/required",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].required",
        "path_kind": "property"
      },
      "purpose": "Whether the claim must be present; a missing required claim denies.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/sensitivity",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].sensitivity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "direct_identifier",
            "personal",
            "public",
            "pseudonymous"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseClaimConfig/properties/source_field",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].source_field",
        "path_kind": "property"
      },
      "purpose": "Source field projected into the claim. XOR with `expression`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseConditionsConfig/properties/expression",
        "key_path": "datasets[].entities[].attribute_release_profiles[].release_conditions.expression",
        "path_kind": "property"
      },
      "purpose": "A single CEL expression evaluated over the subject's source projection.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ReleaseExpressionConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "cel"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseExpressionConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseExpressionConfig/properties/cel",
        "key_path": "datasets[].entities[].attribute_release_profiles[].claims[].expression.cel",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseExpressionConfig/properties/cel",
        "key_path": "datasets[].entities[].attribute_release_profiles[].release_conditions.expression.cel",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseResponseConfig/properties/include_source_metadata",
        "key_path": "datasets[].entities[].attribute_release_profiles[].response.include_source_metadata",
        "path_kind": "property"
      },
      "purpose": "Whether to include profile-sourced metadata in the response body.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseSubjectConfig/properties/id_type",
        "key_path": "datasets[].entities[].attribute_release_profiles[].subject.id_type",
        "path_kind": "property"
      },
      "purpose": "Accepted identifier type label.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ReleaseSubjectConfig/properties/source_field",
        "key_path": "datasets[].entities[].attribute_release_profiles[].subject.source_field",
        "path_kind": "property"
      },
      "purpose": "Source field used to match the subject. Must be an exposed entity field.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/field",
        "key_path": "datasets[].aggregates[].required_filter_bindings[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/field",
        "key_path": "datasets[].entities[].aggregates[].required_filter_bindings[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/field",
        "key_path": "datasets[].entities[].api.required_filter_bindings[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/field",
        "key_path": "datasets[].tables[].aggregates[].required_filter_bindings[].field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/source",
        "key_path": "datasets[].aggregates[].required_filter_bindings[].source",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingSource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "principal_id"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingSource"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/source",
        "key_path": "datasets[].entities[].aggregates[].required_filter_bindings[].source",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingSource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "principal_id"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingSource"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/source",
        "key_path": "datasets[].entities[].api.required_filter_bindings[].source",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingSource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "principal_id"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingSource"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingConfig/properties/source",
        "key_path": "datasets[].tables[].aggregates[].required_filter_bindings[].source",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RequiredFilterBindingSource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "principal_id"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/RequiredFilterBindingSource"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceAccessConfig/properties/aggregate_scope",
        "key_path": "datasets[].tables[].access.aggregate_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceAccessConfig/properties/metadata_scope",
        "key_path": "datasets[].tables[].access.metadata_scope",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceApiConfig/properties/allowed_filters",
        "key_path": "datasets[].tables[].api.allowed_filters",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceApiConfig/properties/allowed_filters/items",
        "key_path": "datasets[].tables[].api.allowed_filters[]",
        "path_kind": "array_item"
      },
      "purpose": "A single allowed filter: field name + permitted operators.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AllowedFilter",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "field",
            "ops"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AllowedFilter"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceApiConfig/properties/default_limit",
        "key_path": "datasets[].tables[].api.default_limit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceApiConfig/properties/max_limit",
        "key_path": "datasets[].tables[].api.max_limit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceApiConfig/properties/require_purpose_header",
        "key_path": "datasets[].tables[].api.require_purpose_header",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/access",
        "key_path": "datasets[].tables[].access",
        "path_kind": "property"
      },
      "purpose": "Resource-level scope assignments. Private tables are not exposed as row\nresources in beta; row access is configured on public entities.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ResourceAccessConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "metadata_scope",
            "aggregate_scope"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ResourceAccessConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/aggregates",
        "key_path": "datasets[].tables[].aggregates",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/aggregates/items",
        "key_path": "datasets[].tables[].aggregates[]",
        "path_kind": "array_item"
      },
      "purpose": "Aggregate declaration: group-by columns, measures, disclosure\ncontrol.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AggregateConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "description",
            "disclosure_control"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AggregateConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/api",
        "key_path": "datasets[].tables[].api",
        "path_kind": "property"
      },
      "purpose": "Resource-level API knobs: per-field filter allowlist, limit caps,\nand the `Data-Purpose` requirement.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ResourceApiConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "default_limit",
            "max_limit"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ResourceApiConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/id",
        "key_path": "datasets[].tables[].id",
        "path_kind": "property"
      },
      "purpose": "Resource identifier within a dataset.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/ResourceId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ResourceId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/materialization",
        "key_path": "datasets[].tables[].materialization",
        "path_kind": "property"
      },
      "purpose": "How a configured private table is registered for query planning.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "snapshot"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/primary_key",
        "key_path": "datasets[].tables[].primary_key",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/refresh",
        "key_path": "datasets[].tables[].refresh",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "mode",
              "interval"
            ],
            [
              "mode"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/schema",
        "key_path": "datasets[].tables[].schema",
        "path_kind": "property"
      },
      "purpose": "Declared resource schema. `strict` is the spec's `strict_schema`\nflag; on mismatch ingestion refuses to register the resource.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SchemaConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "fields"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/SchemaConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceConfig/properties/source",
        "key_path": "datasets[].tables[].source",
        "path_kind": "property"
      },
      "purpose": "Source plugin selection. Tagged on `type:` so HTTP, S3, or additional\ndatabase variants can land additively later.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SourceConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "type",
              "connection_env"
            ],
            [
              "type",
              "path"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceFormatConfig/properties/csv",
        "key_path": "datasets[].tables[].source.format.csv",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceFormatConfig/properties/parquet",
        "key_path": "datasets[].tables[].source.format.parquet",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ResourceFormatConfig/properties/xlsx",
        "key_path": "datasets[].tables[].source.format.xlsx",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RotateConfig/properties/max_files",
        "key_path": "audit.rotate.max_files",
        "path_kind": "property"
      },
      "purpose": "Controls Relay audit event delivery, rotation, integrity chaining, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/RotateConfig/properties/max_size_mb",
        "key_path": "audit.rotate.max_size_mb",
        "path_kind": "property"
      },
      "purpose": "Controls Relay audit event delivery, rotation, integrity chaining, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SchemaConfig/properties/fields",
        "key_path": "datasets[].tables[].schema.fields",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SchemaConfig/properties/fields/items",
        "key_path": "datasets[].tables[].schema.fields[]",
        "path_kind": "array_item"
      },
      "purpose": "One column in a resource schema. Physical type and optional\nsemantic annotations used by catalog and schema metadata.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FieldConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/FieldConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SchemaConfig/properties/strict",
        "key_path": "datasets[].tables[].schema.strict",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/admin_bind",
        "key_path": "server.admin_bind",
        "path_kind": "property"
      },
      "purpose": "Canonical dotted-decimal IPv4 or bracketed IPv6 plus a decimal port from 0 through 65535",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": [
            "^(?:(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9]):(?:0|[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5])$",
            "^\\[(?:(?:[0-9A-Fa-f]{1,4}:){7}[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,7}:|(?:[0-9A-Fa-f]{1,4}:){1,6}:[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,5}(?::[0-9A-Fa-f]{1,4}){1,2}|(?:[0-9A-Fa-f]{1,4}:){1,4}(?::[0-9A-Fa-f]{1,4}){1,3}|(?:[0-9A-Fa-f]{1,4}:){1,3}(?::[0-9A-Fa-f]{1,4}){1,4}|(?:[0-9A-Fa-f]{1,4}:){1,2}(?::[0-9A-Fa-f]{1,4}){1,5}|[0-9A-Fa-f]{1,4}:(?:(?::[0-9A-Fa-f]{1,4}){1,6})|:(?:(?::[0-9A-Fa-f]{1,4}){1,7}|:))\\]:(?:0|[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5])$"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/bind",
        "key_path": "server.bind",
        "path_kind": "property"
      },
      "purpose": "Canonical dotted-decimal IPv4 or bracketed IPv6 plus a decimal port from 0 through 65535",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SocketAddr",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": [
            "^(?:(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9]):(?:0|[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5])$",
            "^\\[(?:(?:[0-9A-Fa-f]{1,4}:){7}[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,7}:|(?:[0-9A-Fa-f]{1,4}:){1,6}:[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,5}(?::[0-9A-Fa-f]{1,4}){1,2}|(?:[0-9A-Fa-f]{1,4}:){1,4}(?::[0-9A-Fa-f]{1,4}){1,3}|(?:[0-9A-Fa-f]{1,4}:){1,3}(?::[0-9A-Fa-f]{1,4}){1,4}|(?:[0-9A-Fa-f]{1,4}:){1,2}(?::[0-9A-Fa-f]{1,4}){1,5}|[0-9A-Fa-f]{1,4}:(?:(?::[0-9A-Fa-f]{1,4}){1,6})|:(?:(?::[0-9A-Fa-f]{1,4}){1,7}|:))\\]:(?:0|[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5])$"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/SocketAddr"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/cache_dir",
        "key_path": "server.cache_dir",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/cors",
        "key_path": "server.cors",
        "path_kind": "property"
      },
      "purpose": "CORS allowlist; default-deny per Section 17 item 7.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CorsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/CorsConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/http1_header_read_timeout",
        "key_path": "server.http1_header_read_timeout",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/max_connections",
        "key_path": "server.max_connections",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/max_source_file_bytes",
        "key_path": "server.max_source_file_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/openapi_requires_auth",
        "key_path": "server.openapi_requires_auth",
        "path_kind": "property"
      },
      "purpose": "Keeps the configured OpenAPI document behind Relay authentication unless an operator explicitly accepts unauthenticated contract discovery.",
      "purpose_source": "reviewed_override",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/request_body_timeout",
        "key_path": "server.request_body_timeout",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/request_timeout",
        "key_path": "server.request_timeout",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/trust_proxy",
        "key_path": "server.trust_proxy",
        "path_kind": "property"
      },
      "purpose": "`X-Forwarded-For` policy. Until the `ipnet` crate lands in deps we\nkeep CIDR specs as strings and validate format in\n[`validate::run`].",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/TrustProxyConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/TrustProxyConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig/properties/xlsx_max_file_bytes",
        "key_path": "server.xlsx_max_file_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "maximum",
          "value": 18446744073709551615
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/0/properties/format",
        "key_path": "datasets[].tables[].source.format",
        "path_kind": "property"
      },
      "purpose": "Storage table format override. If omitted, ingest infers the format\nfrom the source file extension.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/0/properties/path",
        "key_path": "datasets[].tables[].source.path",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/0/properties/type",
        "key_path": "datasets[].tables[].source.type",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "file",
            "postgres"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/1/properties/change_token_sql",
        "key_path": "datasets[].tables[].source.change_token_sql",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/1/properties/connect_timeout",
        "key_path": "datasets[].tables[].source.connect_timeout",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/1/properties/connection_env",
        "key_path": "datasets[].tables[].source.connection_env",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_secret_reference",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/PostgresEnvironmentNameSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[A-Za-z_][A-Za-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/PostgresEnvironmentNameSchema"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/1/properties/query",
        "key_path": "datasets[].tables[].source.query",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/1/properties/query_timeout",
        "key_path": "datasets[].tables[].source.query_timeout",
        "path_kind": "property"
      },
      "purpose": "One or more non-negative integer duration components separated by one ASCII space; supported units are ns, us, ms, s, m, h, d, and w",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 255
        },
        {
          "keyword": "pattern",
          "value": "^[0-9]{1,10}(?:ns|us|ms|s|m|h|d|w)(?: [0-9]{1,10}(?:ns|us|ms|s|m|h|d|w))*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SourceConfig/oneOf/1/properties/table",
        "key_path": "datasets[].tables[].source.table",
        "path_kind": "property"
      },
      "purpose": "Structured database table reference. Keeping schema/name separate\navoids parsing dotted identifiers and leaves quoting to connectors.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "schema",
            "name"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_x",
        "key_path": "datasets[].aggregates[].spatial.bbox_fields.max_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_x",
        "key_path": "datasets[].entities[].aggregates[].spatial.bbox_fields.max_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_x",
        "key_path": "datasets[].entities[].spatial.bbox_fields.max_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_x",
        "key_path": "datasets[].tables[].aggregates[].spatial.bbox_fields.max_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_y",
        "key_path": "datasets[].aggregates[].spatial.bbox_fields.max_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_y",
        "key_path": "datasets[].entities[].aggregates[].spatial.bbox_fields.max_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_y",
        "key_path": "datasets[].entities[].spatial.bbox_fields.max_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/max_y",
        "key_path": "datasets[].tables[].aggregates[].spatial.bbox_fields.max_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_x",
        "key_path": "datasets[].aggregates[].spatial.bbox_fields.min_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_x",
        "key_path": "datasets[].entities[].aggregates[].spatial.bbox_fields.min_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_x",
        "key_path": "datasets[].entities[].spatial.bbox_fields.min_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_x",
        "key_path": "datasets[].tables[].aggregates[].spatial.bbox_fields.min_x",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_y",
        "key_path": "datasets[].aggregates[].spatial.bbox_fields.min_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_y",
        "key_path": "datasets[].entities[].aggregates[].spatial.bbox_fields.min_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_y",
        "key_path": "datasets[].entities[].spatial.bbox_fields.min_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialBboxFieldsConfig/properties/min_y",
        "key_path": "datasets[].tables[].aggregates[].spatial.bbox_fields.min_y",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialGeometryConfig/oneOf/0/properties/crs",
        "key_path": "datasets[].entities[].spatial.geometry.crs",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialGeometryConfig/oneOf/0/properties/kind",
        "key_path": "datasets[].entities[].spatial.geometry.kind",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "geojson",
            "point",
            "wkb",
            "wkt"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialGeometryConfig/oneOf/0/properties/latitude_field",
        "key_path": "datasets[].entities[].spatial.geometry.latitude_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialGeometryConfig/oneOf/0/properties/longitude_field",
        "key_path": "datasets[].entities[].spatial.geometry.longitude_field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpatialGeometryConfig/oneOf/1/properties/field",
        "key_path": "datasets[].entities[].spatial.geometry.field",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/dataset",
        "key_path": "standards.spdci.disability_registry.dataset",
        "path_kind": "property"
      },
      "purpose": "Dataset identifier. Lower-snake, starts with a letter.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DatasetId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DatasetId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/disabled_positive_values",
        "key_path": "standards.spdci.disability_registry.disabled_positive_values",
        "path_kind": "property"
      },
      "purpose": "Case-insensitive values interpreted as disabled.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/disabled_positive_values/items",
        "key_path": "standards.spdci.disability_registry.disabled_positive_values[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/disabled_status_field",
        "key_path": "standards.spdci.disability_registry.disabled_status_field",
        "path_kind": "property"
      },
      "purpose": "Entity field whose value determines the SP DCI disabled response.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/entity",
        "key_path": "standards.spdci.disability_registry.entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/query_field",
        "key_path": "standards.spdci.disability_registry.query_field",
        "path_kind": "property"
      },
      "purpose": "Entity field filtered when the SP DCI query key is present.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciDisabilityRegistryConfig/properties/query_key",
        "key_path": "standards.spdci.disability_registry.query_key",
        "path_kind": "property"
      },
      "purpose": "Query key accepted from SP DCI `disabled_criteria.query`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/dataset",
        "key_path": "standards.spdci.registries.*.dataset",
        "path_kind": "property"
      },
      "purpose": "Dataset identifier. Lower-snake, starts with a letter.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DatasetId",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "pattern",
          "value": "^[a-z][a-z0-9_]*$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DatasetId"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/default_limit",
        "key_path": "standards.spdci.registries.*.default_limit",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/entity",
        "key_path": "standards.spdci.registries.*.entity",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/expression_fields",
        "key_path": "standards.spdci.registries.*.expression_fields",
        "path_kind": "property"
      },
      "purpose": "DCI expression or predicate attribute to entity field mappings.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/expression_fields/additionalProperties",
        "key_path": "standards.spdci.registries.*.expression_fields.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names an expression-visible field and each value defines the bounded source expression exposed under that name.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_spdci_registries_expression_fields_open_map",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/identifiers",
        "key_path": "standards.spdci.registries.*.identifiers",
        "path_kind": "property"
      },
      "purpose": "DCI identifier type to entity field mappings for `idtype-value`.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/identifiers/additionalProperties",
        "key_path": "standards.spdci.registries.*.identifiers.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names an identifier role and each value defines the exact request identifier binding for that role.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_spdci_registries_identifiers_open_map",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/record_type",
        "key_path": "standards.spdci.registries.*.record_type",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/registry_type",
        "key_path": "standards.spdci.registries.*.registry_type",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/response_fields",
        "key_path": "standards.spdci.registries.*.response_fields",
        "path_kind": "property"
      },
      "purpose": "SP DCI output path to entity field mappings for direct response\nprojection. A CEL mapping takes precedence when both are set.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/response_fields/additionalProperties",
        "key_path": "standards.spdci.registries.*.response_fields.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a response field and each value defines the exact bounded response projection for that field.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_spdci_registries_response_fields_open_map",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/response_mapping_path",
        "key_path": "standards.spdci.registries.*.response_mapping_path",
        "path_kind": "property"
      },
      "purpose": "Optional local CEL mapping document used to shape response records.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig/properties/response_schema_path",
        "key_path": "standards.spdci.registries.*.response_schema_path",
        "path_kind": "property"
      },
      "purpose": "Optional local JSON Schema used to validate shaped response records.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciStandardsConfig/properties/disability_registry",
        "key_path": "standards.spdci.disability_registry",
        "path_kind": "property"
      },
      "purpose": "Runtime binding from SP DCI Disability Registry sync APIs to one\nconfigured Registry Relay entity.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "dataset",
            "entity"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciStandardsConfig/properties/registries",
        "key_path": "standards.spdci.registries",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/SpdciStandardsConfig/properties/registries/additionalProperties",
        "key_path": "standards.spdci.registries.*",
        "path_kind": "map_value"
      },
      "purpose": "Runtime binding from a DCI registry sync search API to one configured\nRegistry Relay entity.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_spdci_registries_open_map",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SpdciRegistryConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "dataset",
            "entity"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/SpdciRegistryConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/StandardsConfig/properties/spdci",
        "key_path": "standards.spdci",
        "path_kind": "property"
      },
      "purpose": "Social Protection Digital Convergence Initiative (SP DCI) adapter\nconfiguration.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/TrustProxyConfig/properties/enabled",
        "key_path": "server.trust_proxy.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/TrustProxyConfig/properties/trusted_proxies",
        "key_path": "server.trust_proxy.trusted_proxies",
        "path_kind": "property"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/TrustProxyConfig/properties/trusted_proxies/items",
        "key_path": "server.trust_proxy.trusted_proxies[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Relay listener, transport, timeout, request-limit, and administrative endpoint behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_server_sensitive",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/XlsxFormatConfig/properties/data_range",
        "key_path": "datasets[].tables[].source.format.xlsx.data_range",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/XlsxFormatConfig/properties/header_row",
        "key_path": "datasets[].tables[].source.format.xlsx.header_row",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 4294967295
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/$defs/XlsxFormatConfig/properties/sheet",
        "key_path": "datasets[].tables[].source.format.xlsx.sheet",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/audit",
        "key_path": "audit",
        "path_kind": "property"
      },
      "purpose": "Audit configuration. Sink choice gates further fields via the\ntagged `AuditSinkConfig` enum. The enum is flattened onto the\ncontaining struct so that the YAML `sink:` key acts as the\ndiscriminator, matching the public example configuration.\n\n`deny_unknown_fields` is deliberately omitted here: `serde` does\nnot support combining it with `#[serde(flatten)]` on an internally\ntagged enum (unknown keys in `audit` are caught by the enum's own\n`deny_unknown_fields`).",
      "purpose_source": "schema_description",
      "intent_profile": "relay_audit_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AuditConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "sink",
              "path"
            ],
            [
              "sink"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        },
        {
          "keyword": "unevaluatedProperties",
          "value": false
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuditConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/auth",
        "key_path": "auth",
        "path_kind": "property"
      },
      "purpose": "Authentication configuration. Exactly one of `api_keys` and `oidc`\nis consumed at startup, gated by `mode`; cross-field validation in\n[`validate`] enforces that only the active block is populated.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_auth_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AuthConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "mode"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/AuthConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/catalog",
        "key_path": "catalog",
        "path_kind": "property"
      },
      "purpose": "Catalog-level metadata surfaced by `/metadata/*` and DCAT outputs.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_catalog_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CatalogConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "title",
            "base_url",
            "publisher"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/CatalogConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/config_trust",
        "key_path": "config_trust",
        "path_kind": "property"
      },
      "purpose": "Optional signed configuration bundle trust state.\n\nSimple local deployments omit this block. Bundle-aware deployments pin the\nlocal trust anchor, bundle, and anti-rollback state paths explicitly.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_config_trust_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "trust_anchor_path",
            "bundle_path",
            "antirollback_state_path"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/consultation",
        "key_path": "consultation",
        "path_kind": "property"
      },
      "purpose": "Controls governed consultation execution, reviewed artifacts, credentials, and result handling.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_consultation_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "authorized_workload",
            "state_plane",
            "audit_pseudonym_materials"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/datasets",
        "key_path": "datasets",
        "path_kind": "property"
      },
      "purpose": "Controls Relay dataset, entity, aggregate, source, refresh, disclosure, and access contracts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/datasets/items",
        "key_path": "datasets[]",
        "path_kind": "array_item"
      },
      "purpose": "A single dataset declaration.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_datasets_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DatasetConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "title",
            "description",
            "owner",
            "sensitivity",
            "access_rights",
            "update_frequency"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DatasetConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/deployment",
        "key_path": "deployment",
        "path_kind": "property"
      },
      "purpose": "Declares Relay deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_deployment_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DeploymentConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/DeploymentConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/instance",
        "key_path": "instance",
        "path_kind": "property"
      },
      "purpose": "Stable deployment identity surfaced in redacted operations posture.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_instance_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/InstanceConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/InstanceConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/metadata",
        "key_path": "metadata",
        "path_kind": "property"
      },
      "purpose": "Optional split metadata manifest loaded alongside the runtime config.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_metadata_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "source"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/server",
        "key_path": "server",
        "path_kind": "property"
      },
      "purpose": "HTTP listener and adjacent server-wide knobs.",
      "purpose_source": "schema_description",
      "intent_profile": "relay_server_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ServerConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "bind"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/ServerConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/standards",
        "key_path": "standards",
        "path_kind": "property"
      },
      "purpose": "Controls Relay standards-specific APIs, protocol mappings, and bounded interoperability behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_standards_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/StandardsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "relay",
        "pointer": "/$defs/StandardsConfig"
      }
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/vocabularies",
        "key_path": "vocabularies",
        "path_kind": "property"
      },
      "purpose": "Controls the reviewed vocabulary bindings Relay uses to interpret namespaced terms.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_vocabularies_internal",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "relay",
        "pointer": "/properties/vocabularies/additionalProperties",
        "key_path": "vocabularies.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key is a vocabulary prefix and each value binds that prefix to its operator-approved vocabulary identifier.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "relay_vocabularies_open_map",
      "semantic_owner": "relay_runtime",
      "human_owner": "relay_maintainers",
      "scope": "The complete product-owned Relay runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "relay",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "config.validation_error",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Relay deployment and rollback review before activating changes to runtime bindings, trust, access, or data-serving behavior.",
      "consumers": [
        "registry_relay",
        "docs_generator"
      ],
      "generated_artifacts": [
        "relay_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "relay",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "",
        "key_path": "",
        "path_kind": "root"
      },
      "purpose": "Defines the complete Notary runtime configuration boundary consumed when a Notary instance starts.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_root_structural",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "not_applicable",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "evidence",
            "auth"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/access_token_ttl_seconds",
        "key_path": "auth.access_token_signing.access_token_ttl_seconds",
        "path_kind": "property"
      },
      "purpose": "Access-token lifetime in seconds.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/allowed_algorithms",
        "key_path": "auth.access_token_signing.allowed_algorithms",
        "path_kind": "property"
      },
      "purpose": "Allowed signing algorithms. Only EdDSA is supported.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/allowed_algorithms/items",
        "key_path": "auth.access_token_signing.allowed_algorithms[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/audiences",
        "key_path": "auth.access_token_signing.audiences",
        "path_kind": "property"
      },
      "purpose": "Audiences (`aud`) accepted for Notary-minted access tokens.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/audiences/items",
        "key_path": "auth.access_token_signing.audiences[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/enabled",
        "key_path": "auth.access_token_signing.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/issuer",
        "key_path": "auth.access_token_signing.issuer",
        "path_kind": "property"
      },
      "purpose": "Issuer (`iss`) the Notary stamps into its own access tokens.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/signing_key_id",
        "key_path": "auth.access_token_signing.signing_key_id",
        "path_kind": "property"
      },
      "purpose": "`evidence.signing_keys` entry used to sign access tokens. Must be a\ndedicated key, never a credential-signing key.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/token_typ",
        "key_path": "auth.access_token_signing.token_typ",
        "path_kind": "property"
      },
      "purpose": "Header `typ` stamped into Notary access tokens, distinct from the\ncredential `typ` so a token cannot be replayed as another class.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/verification_key_ids",
        "key_path": "auth.access_token_signing.verification_key_ids",
        "path_kind": "property"
      },
      "purpose": "Additional publish-only `evidence.signing_keys` entries accepted for\nverifying previously minted Notary access tokens and pre-authorized\ncodes during a governed key rotation.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig/properties/verification_key_ids/items",
        "key_path": "auth.access_token_signing.verification_key_ids[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/BatchOperationConfig/properties/enabled",
        "key_path": "evidence.claims[].operations.batch_evaluate.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/BatchOperationConfig/properties/max_subjects",
        "key_path": "evidence.claims[].operations.batch_evaluate.max_subjects",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "maximum",
          "value": 100
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CccevConfig/properties/evidence_type",
        "key_path": "evidence.claims[].cccev.evidence_type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CccevConfig/properties/evidence_type_iri",
        "key_path": "evidence.claims[].cccev.evidence_type_iri",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CccevConfig/properties/requirement_type",
        "key_path": "evidence.claims[].cccev.requirement_type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CelBindingsConfig/properties/claims",
        "key_path": "evidence.claims[].rule.bindings.claims",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CelBindingsConfig/properties/claims/additionalProperties",
        "key_path": "evidence.claims[].rule.bindings.claims.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a CEL claim binding and each value selects the approved evidence claim exposed to that binding.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_claims_rule_bindings_claims_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ClaimBindingConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "claim"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimBindingConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CelBindingsConfig/properties/vars",
        "key_path": "evidence.claims[].rule.bindings.vars",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimBindingConfig/properties/binding_type",
        "key_path": "evidence.claims[].rule.bindings.claims.*.binding_type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimBindingConfig/properties/claim",
        "key_path": "evidence.claims[].rule.bindings.claims.*.claim",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/cccev",
        "key_path": "evidence.claims[].cccev",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/credential_profiles",
        "key_path": "evidence.claims[].credential_profiles",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/credential_profiles/items",
        "key_path": "evidence.claims[].credential_profiles[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/depends_on",
        "key_path": "evidence.claims[].depends_on",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/depends_on/items",
        "key_path": "evidence.claims[].depends_on[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/disclosure",
        "key_path": "evidence.claims[].disclosure",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DisclosureConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/DisclosureConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/evidence_mode",
        "key_path": "evidence.claims[].evidence_mode",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ClaimEvidenceMode",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "type",
              "consultations"
            ],
            [
              "type"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimEvidenceMode"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/formats",
        "key_path": "evidence.claims[].formats",
        "path_kind": "property"
      },
      "purpose": "Omitting this field keeps existing authored claims renderable using the\ncanonical claim-result representation. An explicitly empty list is\nrejected during configuration validation.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/formats/items",
        "key_path": "evidence.claims[].formats[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/id",
        "key_path": "evidence.claims[].id",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/inputs",
        "key_path": "evidence.claims[].inputs",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/inputs/items",
        "key_path": "evidence.claims[].inputs[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ClaimInputConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name",
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimInputConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/oots",
        "key_path": "evidence.claims[].oots",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/operations",
        "key_path": "evidence.claims[].operations",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ClaimOperationsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimOperationsConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/purpose",
        "key_path": "evidence.claims[].purpose",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/required_scopes",
        "key_path": "evidence.claims[].required_scopes",
        "path_kind": "property"
      },
      "purpose": "Caller scopes checked before any registry consultation is dispatched.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/required_scopes/items",
        "key_path": "evidence.claims[].required_scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/rule",
        "key_path": "evidence.claims[].rule",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RuleConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "type",
              "consultation",
              "output"
            ],
            [
              "type",
              "consultation"
            ],
            [
              "type",
              "expression"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RuleConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/semantics",
        "key_path": "evidence.claims[].semantics",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/subject_type",
        "key_path": "evidence.claims[].subject_type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/title",
        "key_path": "evidence.claims[].title",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/value",
        "key_path": "evidence.claims[].value",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ClaimValueConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimValueConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition/properties/version",
        "key_path": "evidence.claims[].version",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimInputConfig/properties/name",
        "key_path": "evidence.claims[].inputs[].name",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimInputConfig/properties/type",
        "key_path": "evidence.claims[].inputs[].type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimOperationsConfig/properties/batch_evaluate",
        "key_path": "evidence.claims[].operations.batch_evaluate",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/BatchOperationConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/BatchOperationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimOperationsConfig/properties/evaluate",
        "key_path": "evidence.claims[].operations.evaluate",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/OperationConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/OperationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimRefObject/properties/id",
        "key_path": "auth.api_keys[].authorization_details.claims[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimRefObject/properties/id",
        "key_path": "auth.bearer_tokens[].authorization_details.claims[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimRefObject/properties/version",
        "key_path": "auth.api_keys[].authorization_details.claims[].version",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimRefObject/properties/version",
        "key_path": "auth.bearer_tokens[].authorization_details.claims[].version",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/concept",
        "key_path": "evidence.claims[].semantics.concept",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/derived_from",
        "key_path": "evidence.claims[].semantics.derived_from",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/derived_from/items",
        "key_path": "evidence.claims[].semantics.derived_from[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/predicate",
        "key_path": "evidence.claims[].semantics.predicate",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/property",
        "key_path": "evidence.claims[].semantics.property",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/value_mapping",
        "key_path": "evidence.claims[].semantics.value_mapping",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimSemanticConfig/properties/vocabulary",
        "key_path": "evidence.claims[].semantics.vocabulary",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimValueConfig/properties/max_bytes",
        "key_path": "evidence.claims[].value.max_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a per-claim string byte ceiling."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "maximum",
          "value": 65536
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimValueConfig/properties/nullable",
        "key_path": "evidence.claims[].value.nullable",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimValueConfig/properties/type",
        "key_path": "evidence.claims[].value.type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ClaimValueConfig/properties/unit",
        "key_path": "evidence.claims[].value.unit",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ConcurrencyConfig/properties/subjects",
        "key_path": "evidence.concurrency.subjects",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ConfigTrustConfig/properties/antirollback_state_path",
        "key_path": "config_trust.antirollback_state_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_config_trust_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ConfigTrustConfig/properties/break_glass_override_path",
        "key_path": "config_trust.break_glass_override_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_config_trust_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ConfigTrustConfig/properties/bundle_path",
        "key_path": "config_trust.bundle_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_config_trust_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/ConfigTrustConfig/properties/trust_anchor_path",
        "key_path": "config_trust.trust_anchor_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary verification of signed configuration bundles, trust anchors, and rollback protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_config_trust_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialDisclosureConfig/properties/allowed",
        "key_path": "evidence.credential_profiles.*.disclosure.allowed",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialDisclosureConfig/properties/allowed/items",
        "key_path": "evidence.credential_profiles.*.disclosure.allowed[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef/properties/name",
        "key_path": "auth.api_keys[].fingerprint.name",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef/properties/name",
        "key_path": "auth.bearer_tokens[].fingerprint.name",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef/properties/path",
        "key_path": "auth.api_keys[].fingerprint.path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef/properties/path",
        "key_path": "auth.bearer_tokens[].fingerprint.path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef/properties/provider",
        "key_path": "auth.api_keys[].fingerprint.provider",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "env",
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef/properties/provider",
        "key_path": "auth.bearer_tokens[].fingerprint.provider",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "env",
            "file"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/allowed_claims",
        "key_path": "evidence.credential_profiles.*.allowed_claims",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/allowed_claims/items",
        "key_path": "evidence.credential_profiles.*.allowed_claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/disclosure",
        "key_path": "evidence.credential_profiles.*.disclosure",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CredentialDisclosureConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/CredentialDisclosureConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/format",
        "key_path": "evidence.credential_profiles.*.format",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/holder_binding",
        "key_path": "evidence.credential_profiles.*.holder_binding",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/HolderBindingConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/HolderBindingConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/issuer",
        "key_path": "evidence.credential_profiles.*.issuer",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/signing_key",
        "key_path": "evidence.credential_profiles.*.signing_key",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/validity_seconds",
        "key_path": "evidence.credential_profiles.*.validity_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int64"
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig/properties/vct",
        "key_path": "evidence.credential_profiles.*.vct",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialStatusConfig/properties/base_url",
        "key_path": "credential_status.base_url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary credential-status publication and retention behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_credential_status_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialStatusConfig/properties/enabled",
        "key_path": "credential_status.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary credential-status publication and retention behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_credential_status_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/CredentialStatusConfig/properties/retention_seconds",
        "key_path": "credential_status.retention_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary credential-status publication and retention behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_credential_status_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentConfig/properties/evidence",
        "key_path": "deployment.evidence",
        "path_kind": "property"
      },
      "purpose": "Declares Notary deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DeploymentEvidenceConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentEvidenceConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentConfig/properties/multi_instance",
        "key_path": "deployment.multi_instance",
        "path_kind": "property"
      },
      "purpose": "Declares Notary deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentConfig/properties/profile",
        "key_path": "deployment.profile",
        "path_kind": "property"
      },
      "purpose": "The set of deployment profiles an operator can declare.\n\nFrozen at introduction; new profiles may be added but existing ones never\nchange meaning. Deserialization is strict: an unknown profile string fails,\nwhich surfaces as a startup error.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "local",
            "hosted_lab",
            "production",
            "evidence_grade"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentConfig/properties/waivers",
        "key_path": "deployment.waivers",
        "path_kind": "property"
      },
      "purpose": "Declares Notary deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentConfig/properties/waivers/items",
        "key_path": "deployment.waivers[]",
        "path_kind": "array_item"
      },
      "purpose": "One operator-configured waiver.\n\nA waiver names exactly one finding id, a required operator reference, an\noptional summary, and a mandatory expiry date (`YYYY-MM-DD`). The shared\noperations contract validates metadata before it can reach posture or logs.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DeploymentWaiverConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "finding",
            "reference",
            "expires"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/audit_ack_cursor_path",
        "key_path": "deployment.evidence.audit_ack_cursor_path",
        "path_kind": "property"
      },
      "purpose": "Optional path to a `registry.audit.ack_cursor.v1` file maintained by\nwhatever ships audit events off-host. Runtime health requires both a\nfresh timestamp and a watermark equal to the live keyed audit-chain tail.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/audit_ack_max_age_secs",
        "key_path": "deployment.evidence.audit_ack_max_age_secs",
        "path_kind": "property"
      },
      "purpose": "Optional freshness window, in seconds, for the off-host ack cursor.\nUnset defaults to [`DEFAULT_AUDIT_ACK_MAX_AGE`] (900s). Meaningless\nwithout `audit_ack_cursor_path`; config load rejects that combination.\n\n[`DEFAULT_AUDIT_ACK_MAX_AGE`]: registry_platform_ops::DEFAULT_AUDIT_ACK_MAX_AGE",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/audit_offhost_shipping",
        "key_path": "deployment.evidence.audit_offhost_shipping",
        "path_kind": "property"
      },
      "purpose": "Operator asserts audit log events are shipped off-host (for example to\na log aggregator or SIEM) so a local file sink does not cap retention.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentEvidenceConfig/properties/signer_custody_approved",
        "key_path": "deployment.evidence.signer_custody_approved",
        "path_kind": "property"
      },
      "purpose": "Operator asserts a production review has approved signer custody for\nthis deployment. Provider kind is not proof of custody: PKCS#11 modules\ncan be backed by either hardware or software tokens.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/expires",
        "key_path": "deployment.waivers[].expires",
        "path_kind": "property"
      },
      "purpose": "Declares Notary deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/finding",
        "key_path": "deployment.waivers[].finding",
        "path_kind": "property"
      },
      "purpose": "Declares Notary deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/reference",
        "key_path": "deployment.waivers[].reference",
        "path_kind": "property"
      },
      "purpose": "Declares Notary deployment posture and reviewed waiver metadata used by operator checks.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DeploymentWaiverReference",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 128
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "pattern",
          "value": "^(?!.*\\.\\.)[A-Za-z0-9._:-]+$"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverReference"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverConfig/properties/summary",
        "key_path": "deployment.waivers[].summary",
        "path_kind": "property"
      },
      "purpose": "Structurally valid deployment-waiver summary. Contextual authorization-value and private-key marker exclusions require semantic producer validation.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/DeploymentWaiverSummary",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "maxLength",
          "value": 256
        },
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentWaiverSummary"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DisclosureConfig/properties/allowed",
        "key_path": "evidence.claims[].disclosure.allowed",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DisclosureConfig/properties/allowed/items",
        "key_path": "evidence.claims[].disclosure.allowed[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DisclosureConfig/properties/default",
        "key_path": "evidence.claims[].disclosure.default",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/DisclosureConfig/properties/downgrade",
        "key_path": "evidence.claims[].disclosure.downgrade",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAssistedAccessContext/properties/channel",
        "key_path": "auth.api_keys[].authorization_details.assisted_access_context.channel",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAssistedAccessContext/properties/channel",
        "key_path": "auth.bearer_tokens[].authorization_details.assisted_access_context.channel",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig/properties/hash_secret_env",
        "key_path": "audit.hash_secret_env",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig/properties/max_files",
        "key_path": "audit.max_files",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig/properties/max_size_mb",
        "key_path": "audit.max_size_mb",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig/properties/path",
        "key_path": "audit.path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig/properties/sink",
        "key_path": "audit.sink",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig/properties/syslog_socket_path",
        "key_path": "audit.syslog_socket_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig/properties/access_token_signing",
        "key_path": "auth.access_token_signing",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/AccessTokenSigningConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/AccessTokenSigningConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig/properties/api_keys",
        "key_path": "auth.api_keys",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig/properties/api_keys/items",
        "key_path": "auth.api_keys[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EvidenceCredentialConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "fingerprint"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig/properties/bearer_tokens",
        "key_path": "auth.bearer_tokens",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig/properties/bearer_tokens/items",
        "key_path": "auth.bearer_tokens[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EvidenceCredentialConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "fingerprint"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig/properties/oidc",
        "key_path": "auth.oidc",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "issuer",
            "jwks_url"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/access_mode",
        "key_path": "auth.api_keys[].authorization_details.access_mode",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "unknown",
            "machine_client",
            "subject_bound",
            "delegated_attestation"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/access_mode",
        "key_path": "auth.bearer_tokens[].authorization_details.access_mode",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "unknown",
            "machine_client",
            "subject_bound",
            "delegated_attestation"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "string"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/actions",
        "key_path": "auth.api_keys[].authorization_details.actions",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/actions",
        "key_path": "auth.bearer_tokens[].authorization_details.actions",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/actions/items",
        "key_path": "auth.api_keys[].authorization_details.actions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/actions/items",
        "key_path": "auth.bearer_tokens[].authorization_details.actions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/assisted_access_context",
        "key_path": "auth.api_keys[].authorization_details.assisted_access_context",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "channel"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/assisted_access_context",
        "key_path": "auth.bearer_tokens[].authorization_details.assisted_access_context",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "channel"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/assurance_level",
        "key_path": "auth.api_keys[].authorization_details.assurance_level",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/assurance_level",
        "key_path": "auth.bearer_tokens[].authorization_details.assurance_level",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/claims",
        "key_path": "auth.api_keys[].authorization_details.claims",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/claims",
        "key_path": "auth.bearer_tokens[].authorization_details.claims",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/claims/items",
        "key_path": "auth.api_keys[].authorization_details.claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object",
          "string"
        ],
        "local_reference": "#/$defs/ClaimRef",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "object",
            "string"
          ]
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimRef"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/claims/items",
        "key_path": "auth.bearer_tokens[].authorization_details.claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object",
          "string"
        ],
        "local_reference": "#/$defs/ClaimRef",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "object",
            "string"
          ]
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimRef"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/consent_ref",
        "key_path": "auth.api_keys[].authorization_details.consent_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/consent_ref",
        "key_path": "auth.bearer_tokens[].authorization_details.consent_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/disclosure",
        "key_path": "auth.api_keys[].authorization_details.disclosure",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/disclosure",
        "key_path": "auth.bearer_tokens[].authorization_details.disclosure",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/format",
        "key_path": "auth.api_keys[].authorization_details.format",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/format",
        "key_path": "auth.bearer_tokens[].authorization_details.format",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/jurisdiction",
        "key_path": "auth.api_keys[].authorization_details.jurisdiction",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/jurisdiction",
        "key_path": "auth.bearer_tokens[].authorization_details.jurisdiction",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/legal_basis_ref",
        "key_path": "auth.api_keys[].authorization_details.legal_basis_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/legal_basis_ref",
        "key_path": "auth.bearer_tokens[].authorization_details.legal_basis_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/locations",
        "key_path": "auth.api_keys[].authorization_details.locations",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/locations",
        "key_path": "auth.bearer_tokens[].authorization_details.locations",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/locations/items",
        "key_path": "auth.api_keys[].authorization_details.locations[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/locations/items",
        "key_path": "auth.bearer_tokens[].authorization_details.locations[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/purpose",
        "key_path": "auth.api_keys[].authorization_details.purpose",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/purpose",
        "key_path": "auth.bearer_tokens[].authorization_details.purpose",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/relationship",
        "key_path": "auth.api_keys[].authorization_details.relationship",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relationship_type",
            "proof_claim"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/relationship",
        "key_path": "auth.bearer_tokens[].authorization_details.relationship",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relationship_type",
            "proof_claim"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/schema_version",
        "key_path": "auth.api_keys[].authorization_details.schema_version",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/schema_version",
        "key_path": "auth.bearer_tokens[].authorization_details.schema_version",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/subject",
        "key_path": "auth.api_keys[].authorization_details.subject",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "binding_claim",
            "id_type"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/subject",
        "key_path": "auth.bearer_tokens[].authorization_details.subject",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "binding_claim",
            "id_type"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/target",
        "key_path": "auth.api_keys[].authorization_details.target",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id_type",
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/target",
        "key_path": "auth.bearer_tokens[].authorization_details.target",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id_type",
            "id"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/type",
        "key_path": "auth.api_keys[].authorization_details.type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationDetails/properties/type",
        "key_path": "auth.bearer_tokens[].authorization_details.type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationRelationship/properties/proof_claim",
        "key_path": "auth.api_keys[].authorization_details.relationship.proof_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationRelationship/properties/proof_claim",
        "key_path": "auth.bearer_tokens[].authorization_details.relationship.proof_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationRelationship/properties/relationship_type",
        "key_path": "auth.api_keys[].authorization_details.relationship.relationship_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationRelationship/properties/relationship_type",
        "key_path": "auth.bearer_tokens[].authorization_details.relationship.relationship_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationSubject/properties/binding_claim",
        "key_path": "auth.api_keys[].authorization_details.subject.binding_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationSubject/properties/binding_claim",
        "key_path": "auth.bearer_tokens[].authorization_details.subject.binding_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationSubject/properties/id_type",
        "key_path": "auth.api_keys[].authorization_details.subject.id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationSubject/properties/id_type",
        "key_path": "auth.bearer_tokens[].authorization_details.subject.id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationTarget/properties/id",
        "key_path": "auth.api_keys[].authorization_details.target.id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationTarget/properties/id",
        "key_path": "auth.bearer_tokens[].authorization_details.target.id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationTarget/properties/id_type",
        "key_path": "auth.api_keys[].authorization_details.target.id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthorizationTarget/properties/id_type",
        "key_path": "auth.bearer_tokens[].authorization_details.target.id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/allowed_purposes",
        "key_path": "evidence.allowed_purposes",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/allowed_purposes/items",
        "key_path": "evidence.allowed_purposes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/api_base_url",
        "key_path": "evidence.api_base_url",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/api_version",
        "key_path": "evidence.api_version",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/claims",
        "key_path": "evidence.claims",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/claims/items",
        "key_path": "evidence.claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ClaimDefinition",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "title",
            "version",
            "subject_type",
            "evidence_mode",
            "rule"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ClaimDefinition"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/claims_url",
        "key_path": "evidence.claims_url",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/concurrency",
        "key_path": "evidence.concurrency",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/ConcurrencyConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/ConcurrencyConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/credential_profiles",
        "key_path": "evidence.credential_profiles",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/credential_profiles/additionalProperties",
        "key_path": "evidence.credential_profiles.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a credential profile and each value defines its exact claims, format, and issuance contract.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_credential_profiles_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CredentialProfileConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "format",
            "issuer",
            "signing_key",
            "vct"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/CredentialProfileConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/enabled",
        "key_path": "evidence.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/formats_url",
        "key_path": "evidence.formats_url",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/inline_batch_limit",
        "key_path": "evidence.inline_batch_limit",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "maximum",
          "value": 100
        },
        {
          "keyword": "minimum",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/machine_quota",
        "key_path": "evidence.machine_quota",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/MachineQuotaConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/MachineQuotaConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/max_credential_validity_seconds",
        "key_path": "evidence.max_credential_validity_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/relay",
        "key_path": "evidence.relay",
        "path_kind": "property"
      },
      "purpose": "The one Registry Relay connection available to registry-backed claims.\nAuthentication remains a reloadable local file reference; core never\nloads the bearer token value.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "base_url",
            "workload_client_id",
            "token_file"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/service_id",
        "key_path": "evidence.service_id",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/signing_keys",
        "key_path": "evidence.signing_keys",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/signing_keys/additionalProperties",
        "key_path": "evidence.signing_keys.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a signing-key binding and each value references the operator-managed signing material and lifecycle metadata.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_signing_keys_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SigningKeyConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "provider",
            "alg",
            "kid",
            "status"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/variables",
        "key_path": "evidence.variables",
        "path_kind": "property"
      },
      "purpose": "Closed union of request variables declared by authored services.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig/properties/variables/additionalProperties",
        "key_path": "evidence.variables.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a Notary evidence variable and each value defines its bounded source and evaluation contract.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_variables_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RequestVariableConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "from",
            "type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RequestVariableConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/authorization_details",
        "key_path": "auth.api_keys[].authorization_details",
        "path_kind": "property"
      },
      "purpose": "Versioned authorization fields shared by static configuration and token/OIDC JSON.\n\nUnknown metadata is intentionally ignored for forward-compatible interoperability.\nAuthorization decisions consume only the modeled fields and must never infer authority\nfrom an unrecognized extension.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "schema_version"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/authorization_details",
        "key_path": "auth.bearer_tokens[].authorization_details",
        "path_kind": "property"
      },
      "purpose": "Versioned authorization fields shared by static configuration and token/OIDC JSON.\n\nUnknown metadata is intentionally ignored for forward-compatible interoperability.\nAuthorization decisions consume only the modeled fields and must never infer authority\nfrom an unrecognized extension.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "type",
            "schema_version"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/fingerprint",
        "key_path": "auth.api_keys[].fingerprint",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CredentialFingerprintRef",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "provider"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/fingerprint",
        "key_path": "auth.bearer_tokens[].fingerprint",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CredentialFingerprintRef",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "provider"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/CredentialFingerprintRef"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/id",
        "key_path": "auth.api_keys[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/id",
        "key_path": "auth.bearer_tokens[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/scopes",
        "key_path": "auth.api_keys[].scopes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/scopes",
        "key_path": "auth.bearer_tokens[].scopes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/scopes/items",
        "key_path": "auth.api_keys[].scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceCredentialConfig/properties/scopes/items",
        "key_path": "auth.bearer_tokens[].scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allow_insecure_localhost",
        "key_path": "auth.oidc.allow_insecure_localhost",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allowed_algorithms",
        "key_path": "auth.oidc.allowed_algorithms",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allowed_algorithms/items",
        "key_path": "auth.oidc.allowed_algorithms[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allowed_clients",
        "key_path": "auth.oidc.allowed_clients",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allowed_clients/items",
        "key_path": "auth.oidc.allowed_clients[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allowed_token_types",
        "key_path": "auth.oidc.allowed_token_types",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/allowed_token_types/items",
        "key_path": "auth.oidc.allowed_token_types[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/audiences",
        "key_path": "auth.oidc.audiences",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/audiences/items",
        "key_path": "auth.oidc.audiences[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/issuer",
        "key_path": "auth.oidc.issuer",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/jwks_url",
        "key_path": "auth.oidc.jwks_url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/leeway",
        "key_path": "auth.oidc.leeway",
        "path_kind": "property"
      },
      "purpose": "A humantime duration string. The runtime parser remains authoritative for its complete grammar.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/principal_claim",
        "key_path": "auth.oidc.principal_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/scope_claim",
        "key_path": "auth.oidc.scope_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/scope_map",
        "key_path": "auth.oidc.scope_map",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/scope_map/additionalProperties",
        "key_path": "auth.oidc.scope_map.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key is an external token scope and each value is the bounded Notary scope mapping granted for that exact token scope.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_oidc_scope_map_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/scope_map/additionalProperties/items",
        "key_path": "auth.oidc.scope_map.*[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/scope_separator",
        "key_path": "auth.oidc.scope_separator",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/userinfo_endpoint",
        "key_path": "auth.oidc.userinfo_endpoint",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/userinfo_issuers",
        "key_path": "auth.oidc.userinfo_issuers",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceOidcAuthConfig/properties/userinfo_issuers/items",
        "key_path": "auth.oidc.userinfo_issuers[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/clock_leeway_seconds",
        "key_path": "federation.clock_leeway_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/emergency_denylist",
        "key_path": "federation.emergency_denylist",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationEmergencyDenylistConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationEmergencyDenylistConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/enabled",
        "key_path": "federation.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/evaluation_profiles",
        "key_path": "federation.evaluation_profiles",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/evaluation_profiles/items",
        "key_path": "federation.evaluation_profiles[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationEvaluationProfileConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "ruleset",
            "claim_id",
            "subject_id_type"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/federation_api",
        "key_path": "federation.federation_api",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/inbound_body_limit_bytes",
        "key_path": "federation.inbound_body_limit_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/issuer",
        "key_path": "federation.issuer",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/jwks_uri",
        "key_path": "federation.jwks_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/max_request_lifetime_seconds",
        "key_path": "federation.max_request_lifetime_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/node_id",
        "key_path": "federation.node_id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/pairwise_subject_hash",
        "key_path": "federation.pairwise_subject_hash",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationPairwiseSubjectHashConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationPairwiseSubjectHashConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/peers",
        "key_path": "federation.peers",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/peers/items",
        "key_path": "federation.peers[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationPeerConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "node_id",
            "issuer",
            "jwks_uri"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/response_shaping",
        "key_path": "federation.response_shaping",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationResponseShapingConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationResponseShapingConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/signing",
        "key_path": "federation.signing",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationSigningConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "signing_key"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationSigningConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/supported_protocol_versions",
        "key_path": "federation.supported_protocol_versions",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig/properties/supported_protocol_versions/items",
        "key_path": "federation.supported_protocol_versions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEmergencyDenylistConfig/properties/kids",
        "key_path": "federation.emergency_denylist.kids",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEmergencyDenylistConfig/properties/kids/items",
        "key_path": "federation.emergency_denylist.kids[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEmergencyDenylistConfig/properties/node_ids",
        "key_path": "federation.emergency_denylist.node_ids",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEmergencyDenylistConfig/properties/node_ids/items",
        "key_path": "federation.emergency_denylist.node_ids[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/assurance_level",
        "key_path": "federation.evaluation_profiles[].assurance_level",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/claim_id",
        "key_path": "federation.evaluation_profiles[].claim_id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/consent_ref",
        "key_path": "federation.evaluation_profiles[].consent_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/disclosure",
        "key_path": "federation.evaluation_profiles[].disclosure",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/id",
        "key_path": "federation.evaluation_profiles[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/jurisdiction",
        "key_path": "federation.evaluation_profiles[].jurisdiction",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/legal_basis_ref",
        "key_path": "federation.evaluation_profiles[].legal_basis_ref",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/max_claim_result_age_seconds",
        "key_path": "federation.evaluation_profiles[].max_claim_result_age_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/ruleset",
        "key_path": "federation.evaluation_profiles[].ruleset",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationEvaluationProfileConfig/properties/subject_id_type",
        "key_path": "federation.evaluation_profiles[].subject_id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPairwiseSubjectHashConfig/properties/secret_env",
        "key_path": "federation.pairwise_subject_hash.secret_env",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allow_insecure_localhost",
        "key_path": "federation.peers[].allow_insecure_localhost",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allow_insecure_private_network",
        "key_path": "federation.peers[].allow_insecure_private_network",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allowed_profiles",
        "key_path": "federation.peers[].allowed_profiles",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allowed_profiles/items",
        "key_path": "federation.peers[].allowed_profiles[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allowed_protocol_versions",
        "key_path": "federation.peers[].allowed_protocol_versions",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allowed_protocol_versions/items",
        "key_path": "federation.peers[].allowed_protocol_versions[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allowed_purposes",
        "key_path": "federation.peers[].allowed_purposes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/allowed_purposes/items",
        "key_path": "federation.peers[].allowed_purposes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/evaluation_scopes",
        "key_path": "federation.peers[].evaluation_scopes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/evaluation_scopes/items",
        "key_path": "federation.peers[].evaluation_scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/issuer",
        "key_path": "federation.peers[].issuer",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/jwks_uri",
        "key_path": "federation.peers[].jwks_uri",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationPeerConfig/properties/node_id",
        "key_path": "federation.peers[].node_id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationResponseShapingConfig/properties/minimum_denial_latency_ms",
        "key_path": "federation.response_shaping.minimum_denial_latency_ms",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/FederationSigningConfig/properties/signing_key",
        "key_path": "federation.signing.signing_key",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/HolderBindingConfig/properties/allowed_did_methods",
        "key_path": "evidence.credential_profiles.*.holder_binding.allowed_did_methods",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/HolderBindingConfig/properties/allowed_did_methods/items",
        "key_path": "evidence.credential_profiles.*.holder_binding.allowed_did_methods[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/HolderBindingConfig/properties/mode",
        "key_path": "evidence.credential_profiles.*.holder_binding.mode",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/HolderBindingConfig/properties/proof_of_possession",
        "key_path": "evidence.credential_profiles.*.holder_binding.proof_of_possession",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/MachineQuotaConfig/properties/enabled",
        "key_path": "evidence.machine_quota.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/MachineQuotaConfig/properties/subjects_per_minute",
        "key_path": "evidence.machine_quota.subjects_per_minute",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/NotaryInstanceConfig/properties/environment",
        "key_path": "instance.environment",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary instance and its deployment environment for operational correlation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_instance_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/NotaryInstanceConfig/properties/id",
        "key_path": "instance.id",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary instance and its deployment environment for operational correlation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_instance_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/NotaryInstanceConfig/properties/jurisdiction",
        "key_path": "instance.jurisdiction",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary instance and its deployment environment for operational correlation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_instance_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/NotaryInstanceConfig/properties/owner",
        "key_path": "instance.owner",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary instance and its deployment environment for operational correlation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_instance_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/NotaryInstanceConfig/properties/public_base_url",
        "key_path": "instance.public_base_url",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary instance and its deployment environment for operational correlation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_instance_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciAuthorizationConfig/properties/require_pkce_method",
        "key_path": "oid4vci.authorization.require_pkce_method",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/accepted_token_audiences",
        "key_path": "oid4vci.accepted_token_audiences",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/accepted_token_audiences/items",
        "key_path": "oid4vci.accepted_token_audiences[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/authorization",
        "key_path": "oid4vci.authorization",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciAuthorizationConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciAuthorizationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/authorization_servers",
        "key_path": "oid4vci.authorization_servers",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/authorization_servers/items",
        "key_path": "oid4vci.authorization_servers[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/credential_configurations",
        "key_path": "oid4vci.credential_configurations",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/credential_configurations/additionalProperties",
        "key_path": "oid4vci.credential_configurations.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names an OpenID4VCI credential configuration and each value defines the advertised and issued credential contract.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_credential_configurations_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciCredentialConfigurationConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "credential_profile",
            "format",
            "scope",
            "vct",
            "display_name"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/credential_endpoint",
        "key_path": "oid4vci.credential_endpoint",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/credential_issuer",
        "key_path": "oid4vci.credential_issuer",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/display",
        "key_path": "oid4vci.display",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/display/items",
        "key_path": "oid4vci.display[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciIssuerDisplayConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "name"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciIssuerDisplayConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/enabled",
        "key_path": "oid4vci.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/nonce",
        "key_path": "oid4vci.nonce",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciNonceConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciNonceConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/nonce_endpoint",
        "key_path": "oid4vci.nonce_endpoint",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/offer_endpoint",
        "key_path": "oid4vci.offer_endpoint",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/pre_authorized_code",
        "key_path": "oid4vci.pre_authorized_code",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciPreAuthorizedCodeConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciPreAuthorizedCodeConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig/properties/proof",
        "key_path": "oid4vci.proof",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciProofConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciProofConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialClaimConfig/properties/display_name",
        "key_path": "oid4vci.credential_configurations.*.claims[].display_name",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialClaimConfig/properties/id",
        "key_path": "oid4vci.credential_configurations.*.claims[].id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialClaimConfig/properties/output_path",
        "key_path": "oid4vci.credential_configurations.*.claims[].output_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialClaimConfig/properties/output_path/items",
        "key_path": "oid4vci.credential_configurations.*.claims[].output_path[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialClaimConfig/properties/sd",
        "key_path": "oid4vci.credential_configurations.*.claims[].sd",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/claim_id",
        "key_path": "oid4vci.credential_configurations.*.claim_id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/claims",
        "key_path": "oid4vci.credential_configurations.*.claims",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/claims/items",
        "key_path": "oid4vci.credential_configurations.*.claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciCredentialClaimConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "output_path",
            "display_name",
            "sd"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialClaimConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/credential_profile",
        "key_path": "oid4vci.credential_configurations.*.credential_profile",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/cryptographic_binding_methods_supported",
        "key_path": "oid4vci.credential_configurations.*.cryptographic_binding_methods_supported",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/cryptographic_binding_methods_supported/items",
        "key_path": "oid4vci.credential_configurations.*.cryptographic_binding_methods_supported[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/display",
        "key_path": "oid4vci.credential_configurations.*.display",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciCredentialDisplayConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/display_name",
        "key_path": "oid4vci.credential_configurations.*.display_name",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/format",
        "key_path": "oid4vci.credential_configurations.*.format",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/proof_signing_alg_values_supported",
        "key_path": "oid4vci.credential_configurations.*.proof_signing_alg_values_supported",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/proof_signing_alg_values_supported/items",
        "key_path": "oid4vci.credential_configurations.*.proof_signing_alg_values_supported[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/scope",
        "key_path": "oid4vci.credential_configurations.*.scope",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialConfigurationConfig/properties/vct",
        "key_path": "oid4vci.credential_configurations.*.vct",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/background_color",
        "key_path": "oid4vci.credential_configurations.*.display.background_color",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/background_image",
        "key_path": "oid4vci.credential_configurations.*.display.background_image",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/description",
        "key_path": "oid4vci.credential_configurations.*.display.description",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/locale",
        "key_path": "oid4vci.credential_configurations.*.display.locale",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/logo",
        "key_path": "oid4vci.credential_configurations.*.display.logo",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/secondary_image",
        "key_path": "oid4vci.credential_configurations.*.display.secondary_image",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciCredentialDisplayConfig/properties/text_color",
        "key_path": "oid4vci.credential_configurations.*.display.text_color",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/alt_text",
        "key_path": "oid4vci.credential_configurations.*.display.background_image.alt_text",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/alt_text",
        "key_path": "oid4vci.credential_configurations.*.display.logo.alt_text",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/alt_text",
        "key_path": "oid4vci.credential_configurations.*.display.secondary_image.alt_text",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/alt_text",
        "key_path": "oid4vci.display[].logo.alt_text",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/uri",
        "key_path": "oid4vci.credential_configurations.*.display.background_image.uri",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/uri",
        "key_path": "oid4vci.credential_configurations.*.display.logo.uri",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/uri",
        "key_path": "oid4vci.credential_configurations.*.display.secondary_image.uri",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/uri",
        "key_path": "oid4vci.display[].logo.uri",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/url",
        "key_path": "oid4vci.credential_configurations.*.display.background_image.url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/url",
        "key_path": "oid4vci.credential_configurations.*.display.logo.url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/url",
        "key_path": "oid4vci.credential_configurations.*.display.secondary_image.url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciDisplayImageConfig/properties/url",
        "key_path": "oid4vci.display[].logo.url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/allow_insecure_localhost",
        "key_path": "oid4vci.pre_authorized_code.esignet.allow_insecure_localhost",
        "path_kind": "property"
      },
      "purpose": "Allow `http` loopback URLs for the eSignet endpoints and JWKS transport.\nFor local development and tests only.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/authorize_url",
        "key_path": "oid4vci.pre_authorized_code.esignet.authorize_url",
        "path_kind": "property"
      },
      "purpose": "eSignet authorize endpoint.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/client_id",
        "key_path": "oid4vci.pre_authorized_code.esignet.client_id",
        "path_kind": "property"
      },
      "purpose": "Confidential client id the Notary presents to eSignet.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/client_signing_key_id",
        "key_path": "oid4vci.pre_authorized_code.esignet.client_signing_key_id",
        "path_kind": "property"
      },
      "purpose": "`evidence.signing_keys` entry used to sign the eSignet\n`private_key_jwt` client assertion.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/issuer",
        "key_path": "oid4vci.pre_authorized_code.esignet.issuer",
        "path_kind": "property"
      },
      "purpose": "eSignet OIDC issuer, pinned when validating the returned `id_token`.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/jwks_uri",
        "key_path": "oid4vci.pre_authorized_code.esignet.jwks_uri",
        "path_kind": "property"
      },
      "purpose": "eSignet JWKS URI, used to resolve the `id_token` signing key by `kid`.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/login_state_ttl_seconds",
        "key_path": "oid4vci.pre_authorized_code.esignet.login_state_ttl_seconds",
        "path_kind": "property"
      },
      "purpose": "Lifetime of the short-lived login state (PKCE verifier + nonce +\nselection) reserved between `offer/start` and `offer/callback`.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/redirect_uri",
        "key_path": "oid4vci.pre_authorized_code.esignet.redirect_uri",
        "path_kind": "property"
      },
      "purpose": "Notary callback the citizen browser is redirected back to.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/scopes",
        "key_path": "oid4vci.pre_authorized_code.esignet.scopes",
        "path_kind": "property"
      },
      "purpose": "OAuth scopes requested at eSignet.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/scopes/items",
        "key_path": "oid4vci.pre_authorized_code.esignet.scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/token_url",
        "key_path": "oid4vci.pre_authorized_code.esignet.token_url",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig/properties/userinfo_url",
        "key_path": "oid4vci.pre_authorized_code.esignet.userinfo_url",
        "path_kind": "property"
      },
      "purpose": "eSignet userinfo endpoint. Required when the subject-binding claim is\nsourced from userinfo rather than the `id_token`; the callback fetches\nthe userinfo JWS with the eSignet access token and reads the binding\nclaim from it.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciIssuerDisplayConfig/properties/locale",
        "key_path": "oid4vci.display[].locale",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciIssuerDisplayConfig/properties/logo",
        "key_path": "oid4vci.display[].logo",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciIssuerDisplayConfig/properties/name",
        "key_path": "oid4vci.display[].name",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciNonceConfig/properties/enabled",
        "key_path": "oid4vci.nonce.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciNonceConfig/properties/ttl_seconds",
        "key_path": "oid4vci.nonce.ttl_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciPreAuthorizedCodeConfig/properties/enabled",
        "key_path": "oid4vci.pre_authorized_code.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciPreAuthorizedCodeConfig/properties/esignet",
        "key_path": "oid4vci.pre_authorized_code.esignet",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciEsignetRpConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciEsignetRpConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciPreAuthorizedCodeConfig/properties/pre_authorized_code_ttl_seconds",
        "key_path": "oid4vci.pre_authorized_code.pre_authorized_code_ttl_seconds",
        "path_kind": "property"
      },
      "purpose": "Pre-authorized-code lifetime in seconds.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciPreAuthorizedCodeConfig/properties/tx_code",
        "key_path": "oid4vci.pre_authorized_code.tx_code",
        "path_kind": "property"
      },
      "purpose": "`tx_code` (PIN) policy for the pre-authorized-code grant. A `tx_code` is\nrequired by default because a code without a PIN is a bearer credential.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciTxCodeConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciTxCodeConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciProofConfig/properties/max_age_seconds",
        "key_path": "oid4vci.proof.max_age_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciProofConfig/properties/max_clock_skew_seconds",
        "key_path": "oid4vci.proof.max_clock_skew_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciTxCodeConfig/properties/input_mode",
        "key_path": "oid4vci.pre_authorized_code.tx_code.input_mode",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciTxCodeConfig/properties/length",
        "key_path": "oid4vci.pre_authorized_code.tx_code.length",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciTxCodeConfig/properties/required",
        "key_path": "oid4vci.pre_authorized_code.tx_code.required",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/authentication_level_of_assurance",
        "key_path": "evidence.claims[].oots.authentication_level_of_assurance",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/enabled",
        "key_path": "evidence.claims[].oots.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/evidence_type_classification",
        "key_path": "evidence.claims[].oots.evidence_type_classification",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/evidence_type_list",
        "key_path": "evidence.claims[].oots.evidence_type_list",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/languages",
        "key_path": "evidence.claims[].oots.languages",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/languages/items",
        "key_path": "evidence.claims[].oots.languages[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/reference_framework",
        "key_path": "evidence.claims[].oots.reference_framework",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OotsConfig/properties/requirement",
        "key_path": "evidence.claims[].oots.requirement",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/OperationConfig/properties/enabled",
        "key_path": "evidence.claims[].operations.evaluate.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryAdminListenerConfig/properties/bind",
        "key_path": "server.admin_listener.bind",
        "path_kind": "property"
      },
      "purpose": "A Rust SocketAddr string. The runtime parser remains authoritative for address and port validity.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SocketAddr",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SocketAddr"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryAdminListenerConfig/properties/mode",
        "key_path": "server.admin_listener.mode",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RegistryNotaryAdminListenerMode",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "shared_with_public",
            "dedicated",
            "disabled"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryAdminListenerMode"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/allow_regex",
        "key_path": "cel.allow_regex",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/eval_timeout_ms",
        "key_path": "cel.eval_timeout_ms",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_binding_json_bytes",
        "key_path": "cel.max_binding_json_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_expression_bytes",
        "key_path": "cel.max_expression_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_list_items",
        "key_path": "cel.max_list_items",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_object_depth",
        "key_path": "cel.max_object_depth",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_object_keys",
        "key_path": "cel.max_object_keys",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_result_json_bytes",
        "key_path": "cel.max_result_json_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/max_string_bytes",
        "key_path": "cel.max_string_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/mode",
        "key_path": "cel.mode",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/worker_count",
        "key_path": "cel.worker_count",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/worker_memory_bytes",
        "key_path": "cel.worker_memory_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig/properties/worker_stderr_bytes",
        "key_path": "cel.worker_stderr_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCorsConfig/properties/allowed_origins",
        "key_path": "server.cors.allowed_origins",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCorsConfig/properties/allowed_origins/items",
        "key_path": "server.cors.allowed_origins[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/admin_listener",
        "key_path": "server.admin_listener",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RegistryNotaryAdminListenerConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryAdminListenerConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/bind",
        "key_path": "server.bind",
        "path_kind": "property"
      },
      "purpose": "A Rust SocketAddr string. The runtime parser remains authoritative for address and port validity.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SocketAddr",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SocketAddr"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/cors",
        "key_path": "server.cors",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RegistryNotaryCorsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCorsConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/http1_header_read_timeout",
        "key_path": "server.http1_header_read_timeout",
        "path_kind": "property"
      },
      "purpose": "A humantime duration string. The runtime parser remains authoritative for its complete grammar.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/max_connections",
        "key_path": "server.max_connections",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/openapi_requires_auth",
        "key_path": "server.openapi_requires_auth",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the reviewed product-owned scalar default; its value is omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/request_body_timeout",
        "key_path": "server.request_body_timeout",
        "path_kind": "property"
      },
      "purpose": "A humantime duration string. The runtime parser remains authoritative for its complete grammar.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/request_timeout",
        "key_path": "server.request_timeout",
        "path_kind": "property"
      },
      "purpose": "A humantime duration string. The runtime parser remains authoritative for its complete grammar.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/HumantimeDuration",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/HumantimeDuration"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/trusted_proxy_ips",
        "key_path": "server.trusted_proxy_ips",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned empty collection required by this runtime contract."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig/properties/trusted_proxy_ips/items",
        "key_path": "server.trusted_proxy_ips[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "ip"
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/allow_insecure_localhost",
        "key_path": "evidence.relay.allow_insecure_localhost",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/allowed_private_cidrs",
        "key_path": "evidence.relay.allowed_private_cidrs",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/allowed_private_cidrs/items",
        "key_path": "evidence.relay.allowed_private_cidrs[]",
        "path_kind": "array_item"
      },
      "purpose": "An IP network CIDR string. The runtime parser remains authoritative for address and prefix validity.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/IpNet",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/IpNet"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/base_url",
        "key_path": "evidence.relay.base_url",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/max_in_flight",
        "key_path": "evidence.relay.max_in_flight",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/token_file",
        "key_path": "evidence.relay.token_file",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConnectionConfig/properties/workload_client_id",
        "key_path": "evidence.relay.workload_client_id",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationConfig/properties/inputs",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.inputs",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationConfig/properties/inputs/additionalProperties",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.inputs.*",
        "path_kind": "map_value"
      },
      "purpose": "A supported consultation input path. The runtime parser remains authoritative for exact stable-name bounds.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_claims_evidence_mode_consultations_inputs_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RelayConsultationInput",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "minLength",
          "value": 1
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationInput"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationConfig/properties/outputs",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs",
        "path_kind": "property"
      },
      "purpose": "Complete closed public output schema expected from the pinned profile.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationConfig/properties/outputs/additionalProperties",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a consultation output and each value defines its bounded evidence-result interpretation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_claims_evidence_mode_consultations_outputs_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RelayOutputContract",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            [
              "type",
              "max_bytes"
            ],
            [
              "type",
              "minimum",
              "maximum"
            ],
            [
              "type"
            ]
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RelayOutputContract"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationConfig/properties/profile",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.profile",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RelayConsultationProfileRef",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "id",
            "contract_hash"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationProfileRef"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationProfileRef/properties/contract_hash",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.profile.contract_hash",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationProfileRef/properties/id",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.profile.id",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayOutputContract/oneOf/0/properties/nullable",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs.*.nullable",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayOutputContract/oneOf/0/properties/type",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs.*.type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "boolean",
            "date",
            "integer",
            "string"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayOutputContract/oneOf/1/properties/maximum",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs.*.maximum",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int64"
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayOutputContract/oneOf/1/properties/minimum",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs.*.minimum",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "int64"
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RelayOutputContract/oneOf/2/properties/max_bytes",
        "key_path": "evidence.claims[].evidence_mode.consultations.*.outputs.*.max_bytes",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RequestVariableConfig/properties/from",
        "key_path": "evidence.variables.*.from",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RequestVariableConfig/properties/type",
        "key_path": "evidence.variables.*.type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/RequestVariableType",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "date"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RequestVariableType"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RuleConfig/oneOf/0/properties/consultation",
        "key_path": "evidence.claims[].rule.consultation",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RuleConfig/oneOf/0/properties/output",
        "key_path": "evidence.claims[].rule.output",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RuleConfig/oneOf/0/properties/type",
        "key_path": "evidence.claims[].rule.type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "cel",
            "consultation_matched",
            "consultation_output"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RuleConfig/oneOf/2/properties/bindings",
        "key_path": "evidence.claims[].rule.bindings",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CelBindingsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/CelBindingsConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/RuleConfig/oneOf/2/properties/expression",
        "key_path": "evidence.claims[].rule.expression",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SealedClaimEvidenceMode/oneOf/0/properties/consultations",
        "key_path": "evidence.claims[].evidence_mode.consultations",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SealedClaimEvidenceMode/oneOf/0/properties/consultations/additionalProperties",
        "key_path": "evidence.claims[].evidence_mode.consultations.*",
        "path_kind": "map_value"
      },
      "purpose": "Each reviewed key names a Relay consultation and each value defines the bounded consultation contract used to support this evidence claim.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_claims_evidence_mode_consultations_open_map",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RelayConsultationConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "structural",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "arbitrary_map_keys_not_fixed_properties"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "profile",
            "inputs"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RelayConsultationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SealedClaimEvidenceMode/oneOf/0/properties/type",
        "key_path": "evidence.claims[].evidence_mode.type",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "const",
          "value": [
            "registry_backed",
            "self_attested"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/alg",
        "key_path": "evidence.signing_keys.*.alg",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/key_id_hex",
        "key_path": "evidence.signing_keys.*.key_id_hex",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/key_label",
        "key_path": "evidence.signing_keys.*.key_label",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/kid",
        "key_path": "evidence.signing_keys.*.kid",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/module_path",
        "key_path": "evidence.signing_keys.*.module_path",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/password_env",
        "key_path": "evidence.signing_keys.*.password_env",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/path",
        "key_path": "evidence.signing_keys.*.path",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/pin_env",
        "key_path": "evidence.signing_keys.*.pin_env",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/private_jwk_env",
        "key_path": "evidence.signing_keys.*.private_jwk_env",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/provider",
        "key_path": "evidence.signing_keys.*.provider",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SigningKeyProviderSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "local_jwk_env",
            "file_watch",
            "pkcs11",
            "local_pkcs12_file",
            "kms",
            "workload_identity"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyProviderSchema"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/public_jwk_env",
        "key_path": "evidence.signing_keys.*.public_jwk_env",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/publish_until_unix_seconds",
        "key_path": "evidence.signing_keys.*.publish_until_unix_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer",
          "null"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": [
            "integer",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/status",
        "key_path": "evidence.signing_keys.*.status",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SigningKeyStatusSchema",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "active",
            "publish_only",
            "disabled"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyStatusSchema"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SigningKeyConfig/properties/token_label",
        "key_path": "evidence.signing_keys.*.token_label",
        "path_kind": "property"
      },
      "purpose": "Controls evidence claims, Relay consultations, disclosure, signing keys, variables, and credential profiles.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_evidence_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StateConfig/properties/postgresql",
        "key_path": "state.postgresql",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/StatePostgresqlConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StateConfig/properties/storage",
        "key_path": "state.storage",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig/properties/connect_timeout_ms",
        "key_path": "state.postgresql.connect_timeout_ms",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig/properties/max_connections",
        "key_path": "state.postgresql.max_connections",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig/properties/operation_timeout_ms",
        "key_path": "state.postgresql.operation_timeout_ms",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig/properties/root_certificate_path",
        "key_path": "state.postgresql.root_certificate_path",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig/properties/sensitive_state_key_env",
        "key_path": "state.postgresql.sensitive_state_key_env",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/StatePostgresqlConfig/properties/url_env",
        "key_path": "state.postgresql.url_env",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_secret_reference",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "secret_reference",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "secret_never_reportable"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessCitizenClientsConfig/properties/allowed_audiences",
        "key_path": "subject_access.citizen_clients.allowed_audiences",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessCitizenClientsConfig/properties/allowed_audiences/items",
        "key_path": "subject_access.citizen_clients.allowed_audiences[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessCitizenClientsConfig/properties/allowed_client_ids",
        "key_path": "subject_access.citizen_clients.allowed_client_ids",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessCitizenClientsConfig/properties/allowed_client_ids/items",
        "key_path": "subject_access.citizen_clients.allowed_client_ids[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_claims",
        "key_path": "subject_access.allowed_claims",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_claims/items",
        "key_path": "subject_access.allowed_claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_disclosures",
        "key_path": "subject_access.allowed_disclosures",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_disclosures/items",
        "key_path": "subject_access.allowed_disclosures[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_formats",
        "key_path": "subject_access.allowed_formats",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_formats/items",
        "key_path": "subject_access.allowed_formats[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_operations",
        "key_path": "subject_access.allowed_operations",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessOperationsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessOperationsConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_purposes",
        "key_path": "subject_access.allowed_purposes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_purposes/items",
        "key_path": "subject_access.allowed_purposes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_wallet_origins",
        "key_path": "subject_access.allowed_wallet_origins",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/allowed_wallet_origins/items",
        "key_path": "subject_access.allowed_wallet_origins[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/citizen_clients",
        "key_path": "subject_access.citizen_clients",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessCitizenClientsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessCitizenClientsConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/credential_profiles",
        "key_path": "subject_access.credential_profiles",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/credential_profiles/items",
        "key_path": "subject_access.credential_profiles[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/delegation",
        "key_path": "subject_access.delegation",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessDelegationConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/enabled",
        "key_path": "subject_access.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/rate_limits",
        "key_path": "subject_access.rate_limits",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessRateLimitsConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/required_scopes",
        "key_path": "subject_access.required_scopes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/required_scopes/items",
        "key_path": "subject_access.required_scopes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/scope_policy",
        "key_path": "subject_access.scope_policy",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SubjectAccessScopePolicy",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "required",
            "optional",
            "disabled"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessScopePolicy"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/subject_binding",
        "key_path": "subject_access.subject_binding",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessSubjectBindingConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig/properties/token_policy",
        "key_path": "subject_access.token_policy",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessTokenPolicyConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_claims",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_claims",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_claims/items",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_claims[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_disclosures",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_disclosures",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_disclosures/items",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_disclosures[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_formats",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_formats",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_formats/items",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_formats[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_purposes",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_purposes",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/allowed_purposes/items",
        "key_path": "subject_access.delegation.allowed_relationships[].allowed_purposes[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/credential_profiles",
        "key_path": "subject_access.delegation.allowed_relationships[].credential_profiles",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/credential_profiles/items",
        "key_path": "subject_access.delegation.allowed_relationships[].credential_profiles[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/proof_claim",
        "key_path": "subject_access.delegation.allowed_relationships[].proof_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/relationship_type",
        "key_path": "subject_access.delegation.allowed_relationships[].relationship_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig/properties/target_id_type",
        "key_path": "subject_access.delegation.allowed_relationships[].target_id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": [
            "string",
            "null"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegationConfig/properties/allowed_relationships",
        "key_path": "subject_access.delegation.allowed_relationships",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegationConfig/properties/allowed_relationships/items",
        "key_path": "subject_access.delegation.allowed_relationships[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessDelegatedRelationshipConfig",
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "relationship_type",
            "proof_claim"
          ]
        },
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegatedRelationshipConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessDelegationConfig/properties/enabled",
        "key_path": "subject_access.delegation.enabled",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessOperationsConfig/properties/batch_evaluate",
        "key_path": "subject_access.allowed_operations.batch_evaluate",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessOperationsConfig/properties/evaluate",
        "key_path": "subject_access.allowed_operations.evaluate",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessOperationsConfig/properties/issue_credential",
        "key_path": "subject_access.allowed_operations.issue_credential",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessOperationsConfig/properties/render",
        "key_path": "subject_access.allowed_operations.render",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig/properties/credential_issuance_per_principal_per_hour",
        "key_path": "subject_access.rate_limits.credential_issuance_per_principal_per_hour",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig/properties/invalid_token_per_client_address_per_minute",
        "key_path": "subject_access.rate_limits.invalid_token_per_client_address_per_minute",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig/properties/per_holder_per_hour",
        "key_path": "subject_access.rate_limits.per_holder_per_hour",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig/properties/per_principal_per_minute",
        "key_path": "subject_access.rate_limits.per_principal_per_minute",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig/properties/subject_mismatch_per_principal_per_hour",
        "key_path": "subject_access.rate_limits.subject_mismatch_per_principal_per_hour",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessRateLimitsConfig/properties/tx_code_attempts_per_code_per_minute",
        "key_path": "subject_access.rate_limits.tx_code_attempts_per_code_per_minute",
        "path_kind": "property"
      },
      "purpose": "Per-minute cap on `tx_code` attempts against a single\n`pre-authorized_code`. Bounds brute force of the numeric PIN at the\npre-authorized-code token endpoint. Defaults to zero so existing\nconfigs that do not enable pre-auth still validate; it must be greater\nthan zero only when the pre-authorized-code flow is enabled.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint32"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig/properties/allow_sub_as_civil_id",
        "key_path": "subject_access.subject_binding.allow_sub_as_civil_id",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "boolean"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "boolean"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig/properties/claim_source",
        "key_path": "subject_access.subject_binding.claim_source",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SubjectAccessClaimSource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "access_token",
            "userinfo"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessClaimSource"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig/properties/id_type",
        "key_path": "subject_access.subject_binding.id_type",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig/properties/normalize",
        "key_path": "subject_access.subject_binding.normalize",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SubjectBindingNormalize",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "exact"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectBindingNormalize"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig/properties/request_field",
        "key_path": "subject_access.subject_binding.request_field",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SubjectId",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "SubjectId"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectId"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessSubjectBindingConfig/properties/token_claim",
        "key_path": "subject_access.subject_binding.token_claim",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/assurance_claim_source",
        "key_path": "subject_access.token_policy.assurance_claim_source",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "local_reference": "#/$defs/SubjectAccessAssuranceClaimSource",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "rejected",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "enum",
          "value": [
            "access_token",
            "id_token"
          ]
        },
        {
          "keyword": "type",
          "value": "string"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessAssuranceClaimSource"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/max_access_token_lifetime_seconds",
        "key_path": "subject_access.token_policy.max_access_token_lifetime_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/max_auth_age_seconds",
        "key_path": "subject_access.token_policy.max_auth_age_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/max_clock_leeway_seconds",
        "key_path": "subject_access.token_policy.max_clock_leeway_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/max_credential_validity_seconds",
        "key_path": "subject_access.token_policy.max_credential_validity_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/max_evaluation_age_seconds",
        "key_path": "subject_access.token_policy.max_evaluation_age_seconds",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "integer"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "format",
          "value": "uint64"
        },
        {
          "keyword": "minimum",
          "value": 0
        },
        {
          "keyword": "type",
          "value": "integer"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/required_acr_values",
        "key_path": "subject_access.token_policy.required_acr_values",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "array"
        ],
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "array"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessTokenPolicyConfig/properties/required_acr_values/items",
        "key_path": "subject_access.token_policy.required_acr_values[]",
        "path_kind": "array_item"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "string"
        ],
        "composed": false
      },
      "requiredness": "not_applicable",
      "null_behavior": "rejected",
      "empty_behavior": "allowed",
      "default": {
        "behavior": "not_applicable"
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "string"
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/audit",
        "key_path": "audit",
        "path_kind": "property"
      },
      "purpose": "Controls Notary audit delivery, retention, hashing, and failure behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_audit_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EvidenceAuditConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuditConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/auth",
        "key_path": "auth",
        "path_kind": "property"
      },
      "purpose": "Controls Notary caller authentication, authorization details, token verification, and access-token signing.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_auth_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EvidenceAuthConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceAuthConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/cel",
        "key_path": "cel",
        "path_kind": "property"
      },
      "purpose": "Controls bounded CEL evaluation limits used by reviewed Notary policy expressions.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_cel_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RegistryNotaryCelConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryCelConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/config_trust",
        "key_path": "config_trust",
        "path_kind": "property"
      },
      "purpose": "Optional governed-configuration local trust state.\n\nSimple local deployments omit this block. Signed/governed apply requires it\nso anti-rollback state lives in an explicit durable location.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_config_trust_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "null",
          "object"
        ],
        "composed": true
      },
      "requiredness": "optional",
      "null_behavior": "conditional",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization preserves the product-owned absence state without materializing a configuration value."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "required",
          "value": [
            "trust_anchor_path",
            "bundle_path",
            "antirollback_state_path"
          ]
        },
        {
          "keyword": "type",
          "value": [
            "null",
            "object"
          ]
        }
      ]
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/credential_status",
        "key_path": "credential_status",
        "path_kind": "property"
      },
      "purpose": "Controls Notary credential-status publication and retention behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_credential_status_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/CredentialStatusConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/CredentialStatusConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/deployment",
        "key_path": "deployment",
        "path_kind": "property"
      },
      "purpose": "The operator-declared `deployment` config block.\n\nAn absent profile means an undeclared deployment, which refuses startup. The\n`multi_instance` flag is an operator declaration that the instance is one of\nseveral sharing the same workload; it is never inferred.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_deployment_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/DeploymentConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/DeploymentConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/evidence",
        "key_path": "evidence",
        "path_kind": "property"
      },
      "purpose": "Registry Notary configuration. Disabled by default so existing\nRegistry Relay deployments load unchanged.",
      "purpose_source": "schema_description",
      "intent_profile": "notary_evidence_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/EvidenceConfig",
        "composed": false
      },
      "requiredness": "required",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "no_schema_default"
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/EvidenceConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/federation",
        "key_path": "federation",
        "path_kind": "property"
      },
      "purpose": "Controls Notary federation trust, request verification, pairwise identifiers, and bounded peer behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_federation_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/FederationConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/FederationConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/instance",
        "key_path": "instance",
        "path_kind": "property"
      },
      "purpose": "Identifies the Notary instance and its deployment environment for operational correlation.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_instance_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/NotaryInstanceConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/NotaryInstanceConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/oid4vci",
        "key_path": "oid4vci",
        "path_kind": "property"
      },
      "purpose": "Controls Notary OpenID4VCI issuer, client, grant, proof, nonce, and credential-configuration behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_oid4vci_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/Oid4vciConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/Oid4vciConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/server",
        "key_path": "server",
        "path_kind": "property"
      },
      "purpose": "Controls Notary listeners, transport, timeouts, request limits, and administrative endpoints.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_server_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/RegistryNotaryHttpConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "schema_default",
        "reviewed_behavior": "The product-owned JSON Schema publishes the default; its value is intentionally omitted from this value-free reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/RegistryNotaryHttpConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/state",
        "key_path": "state",
        "path_kind": "property"
      },
      "purpose": "Controls Notary durable state storage, database trust, timeouts, connection limits, and sensitive-state protection.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_state_internal",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/StateConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "bound_by_environment",
      "sensitivity": "internal",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/StateConfig"
      }
    },
    {
      "address": {
        "schema": "notary",
        "pointer": "/properties/subject_access",
        "key_path": "subject_access",
        "path_kind": "property"
      },
      "purpose": "Controls Notary subject and assisted-access policy, authorization details, and relationship proof behavior.",
      "purpose_source": "reviewed_profile",
      "intent_profile": "notary_subject_access_sensitive",
      "semantic_owner": "notary_runtime",
      "human_owner": "notary_maintainers",
      "scope": "The complete product-owned Notary runtime configuration accepted by schema validation, Rust deserialization, and operator preflight.",
      "field_type": {
        "schema_types": [
          "object"
        ],
        "local_reference": "#/$defs/SubjectAccessConfig",
        "composed": false
      },
      "requiredness": "optional",
      "null_behavior": "rejected",
      "empty_behavior": "not_applicable",
      "default": {
        "behavior": "reviewed_runtime_default",
        "reviewed_behavior": "When omitted, Rust deserialization supplies the product-owned nested default contract; no deployment value is copied into this reference."
      },
      "environment_behavior": "narrows_reviewed_authority",
      "sensitivity": "sensitive",
      "state": "runtime",
      "products": [
        "notary",
        "docs"
      ],
      "availability": "published",
      "stability": "experimental",
      "validation_stages": [
        "json_schema",
        "rust_deserialization",
        "operator_preflight"
      ],
      "diagnostic": "Notary runtime configuration does not yet publish a closed general diagnostic code; doctor reports the generic failed status.",
      "history_status": "not_verified",
      "introduced_in": null,
      "version_history": [],
      "example": {
        "guidance": "Use synthetic identifiers and non-routable placeholders; never copy credentials, environment values, deployment paths, or country configuration.",
        "schema_examples_available": false,
        "contains_country_values": false
      },
      "migration": "coordinate_deployment",
      "migration_note": "Coordinate Notary deployment, key or trust rotation, and rollback review before activating runtime configuration changes.",
      "consumers": [
        "registry_notary",
        "docs_generator"
      ],
      "generated_artifacts": [
        "notary_config",
        "field_reference"
      ],
      "review_classes": [
        "contract",
        "notary",
        "security",
        "privacy",
        "documentation"
      ],
      "semantic_rules": [
        "knowledge_only",
        "generated_docs_never_load_country_values",
        "sensitive_operational_metadata",
        "array_items_share_element_contract"
      ],
      "constraints": [
        {
          "keyword": "type",
          "value": "object"
        }
      ],
      "local_reference": {
        "schema": "notary",
        "pointer": "/$defs/SubjectAccessConfig"
      }
    }
  ]
}
