# Per-workspace acceptance receipt

Candidate 1.6.0-rc.4; run against the newly installed bytes.

Use after import, after bootstrap/regeneration and after schedule migration. Record host app/build,
OS, package and generated versions, immutable workspace ID, actual test time, route and evidence.
Use synthetic or approved bounded test resources; never intentionally open another client's data.
No real spend, client send, destructive test or credential exposure is authorized by this checklist.

| Gate | PASS evidence | Failure means |
|---|---|---|
| Installed bytes | Version, full content SHA, all referenced files readable | Fix installation, not a misleading Save card |
| Host context | Current session and actual authorized host folder resolve same immutable workspace | Pending host access; cloud sandbox not equivalent |
| Bridge | Flat request, done last; accepted claim remains RUNNING; matching completion and correct tenant; no exposed secret | Observe accepted request by same ID; short silence is inconclusive; disconnected only by full silence/missing-channel contract |
| Provider | Small authorized read through Outloop with expected immutable resource and actual provider success | A grant preflight alone is insufficient |
| PM worker | Live account/user ID and in-scope assigned test item; unrelated assignee not executed | Correct identity/binding; don't guess from display name |
| Occurrence | Same durable source/cycle polled twice causes no second execution; next declared cycle runs once | Fix stable generation reference or stale claim via supported owner flow |
| Policy fallback | Safe fixture of technical gap selects MCP before browser when permitted; denial stops refused action | No cross-route denial bypass; don't break production to simulate it |
| Browser | Actual bound route reachable, account verified, no unattended approval hang | Route unproven, not a Playwright/Chrome default assumption |
| Partial method | Approved source asset or alternate method meets constraints and is read back | No premature Stuck; no weakening logo/numeric/output constraints |
| Recovery strategies | Three meaningful available methods fail, early success stops, unavailable routes evaluated only, real budget/refusal respected | No artificial third call or three-call ceiling |
| Missing structure | Evidence-based prototype meets exact constraints; unsupported formula/identity remain UNKNOWN | Approximation cannot be claimed exact |
| Uncertain write | Read-back/operation lookup before any fallback repeat | Tool change does not create a second write budget |
| Mail | Approved internal test delivery: actual provider message ID and stored-copy recipients/body | Draft/preflight is not a send; client-send gate still independent |
| Schedule storage | Correct host, folder, real scope or authorized exception, exact cadence/timezone/next run | No silent global fallback, hourly escalation or guessed timezone |
| Controlled firing | This trigger's run reaches bridge and ends with reconciled manifest/report/finalize where applicable | Step 0 and scheduler SUCCEEDED alone aren't enough |
| Autonomous firing | Subsequent actual cadence run completes without human intervention | Still pending unattended proof |
| Restart/interruption | Missing terminal receipt is surfaced, resumed work reconciles claims safely | No silent short runs or invented completion |
| Safe cutover | Old stopped/drained before new active; one enabled dispatcher/owner | Pause and resolve overlap before business execution |
| Fresh window | Short business request loads current skills/context and produces equivalent valid output | Reflect and repair correct owner rather than prompt bloat |

For unsupported or forbidden capabilities mark NOT_PROVEN/NOT_ENABLED, not PASS. Some negative
cases must remain synthetic; label them STATIC/SIMULATED, never live tenancy proof. An approved
read-only deployment may exclude email or spend, but its sign-off must say exactly what is enabled.
A missing gate for an advertised capability prevents full production sign-off for that capability.

Return: gate, status, request/session/artifact reference, observed result, remaining risk, owner.
Keep private receipts in tenant storage. A public website receives only sanitized aggregate proof.
Do not promote this release from candidate to stable before required host/app import and live gates
are signed off by the release owner. A test helper cannot sign off its own execution policy.
