{"packetVersion":"2026-08-02.fe13.activation-evidence","status":"owner_gated","canonicalPage":"/activation/evidence","rules":["Record source, build, deploy, runtime, browser, provider, and manual interaction proof separately.","Redact secrets, reusable credentials, raw tokens, private owner identifiers, and unnecessary object keys.","Stop at gates until the owner approves exact records, accounts, providers, media, monitoring, or payment scope."],"lanes":[{"label":"Source and runtime","purpose":"Tie every launch claim to a source commit, built image, deployed revision, routed traffic, fresh health probe, and browser-visible route.","fields":["Source commit SHA and evidence commit SHA","Cloud Build ID, image tag, Cloud Run revision, and traffic percent","Production URL, health probe timestamp, HTTP status, and response byte count","Browser route, viewport, interaction checked, and screenshot filename when captured"],"artifacts":["Cloud Build result URL or ID","Cloud Run service metadata readback","Fresh curl or browser proof for tiredevents.com and tired.events","Any screenshot with route, viewport, and timestamp in the note"],"stop":"A 200 response or matching image tag is not enough by itself; record source, deploy, runtime, and user-visible proof separately."},{"label":"Operator-owned event","purpose":"Prove discovery, event detail, checkout quote, ticket wallet, scanner, gallery, reviews, and host analytics against a real approved event.","fields":["Event id, slug, host account, published or scheduled state, start date, venue, city, and coordinates","Ticket tier id, price, available quantity, cart quote subtotal, fee, estimated total, and no-order boundary","Event detail metadata and Event JSON-LD fields observed in production","Host workspace, analytics, sales, scan, review, and buyer visibility routes checked"],"artifacts":["Public event list and detail screenshots","Cart quote response with non-secret identifiers redacted where needed","Host analytics or ticket wallet screenshots approved for notes","Access-denied proof for accounts that should not manage the event"],"stop":"Do not seed fake public inventory, fabricate tickets, or run a charge only to make event proof pass."},{"label":"Operator-owned service","purpose":"Prove services marketplace list, detail metadata, provider ownership, booking boundary, and Connect readiness with an approved provider record.","fields":["Service id, slug, provider account, listed or draft state, category, city, and pricing model","Public list/detail visibility and Service JSON-LD fields for listed records","Provider workspace route and owner account used for readback","Booking or Connect boundary reached, including fail-closed copy when payable state is unavailable"],"artifacts":["Public services list and detail screenshots","Provider dashboard readback with secrets hidden","Connect or booking boundary screenshot","Draft/private denial proof from a non-provider account"],"stop":"Do not invent provider rows, imply Connect readiness from source checks, or expose draft services as payable."},{"label":"Authorized role accounts","purpose":"Record which approved sessions proved buyer, host, provider, promoter, manager, scanner, and admin access without preserving reusable credentials.","fields":["Role name, account alias, approval source, auth method, and verified or unverified state","Allowed routes reached and denied routes confirmed","Account switching, onboarding, posting, collaboration, scanning, settings, and admin preview checks performed","Evidence storage location with tokens, passwords, cookies, and private owner identifiers excluded"],"artifacts":["Route screenshots with account identifiers minimized","Denied-route screenshots for role boundaries","Auth state notes that do not include credentials","Manual session log with operator present when private accounts are used"],"stop":"Do not store reusable credentials, session tokens, cookies, or private owner account screenshots in repo or durable notes."},{"label":"Stripe and Connect proof","purpose":"Capture owner-approved payment, webhook, refund, Connect, Tax, Radar, KYC, payout, and balance evidence without treating source readiness as financial proof.","fields":["Stripe account, mode, Connect account, webhook endpoint alias, and signing-secret confirmation without secret values","Checkout session id, payment intent id, order id, ticket fulfillment id, and webhook delivery id","Refund id, refund state, balance transaction, transfer or payout boundary, and settlement view","Tax, Radar, KYC, Connect onboarding, and payout evidence source with timestamp"],"artifacts":["Stripe dashboard screenshots approved by the owner","Webhook delivery readback with secrets redacted","Application order/ticket readback after webhook fulfillment","Refund, Connect, payout, Tax, Radar, or KYC screenshots when authorized"],"stop":"Do not run charges, refunds, transfers, payouts, or bank-affecting checks without explicit owner approval for exact mode and scope."},{"label":"Media grants and exports","purpose":"Prove approved public, unlisted, private, protected grant, signed URL, manifest, ZIP, and native save/share behavior against real media without mutating originals.","fields":["Gallery id, owner account, visibility mode, object aliases, and non-owner account used for denial checks","Signed upload URL expiry, signed read URL expiry, protected grant claim, and denied private access result","Manifest record count, ZIP filename, ZIP SHA-256, and included visibility set","Native share, copy, save, or download behavior checked on approved desktop/mobile devices"],"artifacts":["Gallery list/detail screenshots by visibility mode","Signed URL success and expiry-denial notes","Manifest and ZIP integrity readback","Native share/save screenshots using approved media only"],"stop":"Do not upload, expose, merge, delete, transform, or redistribute real media without explicit approval and preservation of originals."},{"label":"Operational monitoring","purpose":"Turn FE-11/FE-12 from read-only readiness into owner-approved alert, SLO, error, trace, and rollback proof.","fields":["Alert policy ids, channel ids, recipients, escalation path, and owner approval","Uptime, 5xx/error rate, latency, failed deploy, checkout/webhook, and media-delivery test timestamps","SLO names, error budget posture, Error Reporting window, trace window, and log query references","Rollback or traffic-shift runbook revision, image, reason, operator, and post-change behavior"],"artifacts":["Provider metadata readback for alert policies and channels","Notification delivery proof to approved recipients","SLO, error, trace, and logging screenshots","Rollback drill or traffic-shift evidence note"],"stop":"Do not create channels, page people, mutate provider monitoring, or run drills that affect users without owner sign-off."}]}