<!-- Generated by scripts/generate-gate-one-artifacts.mjs. Do not edit manually. -->
# Gate One V2 Policy 2.3.0

Policy ID: `gate-one-v2-mvp`
Policy digest: `sha256:e11473479041d187a246d63bf3da0dbe632c62acbc6a8f25f55f30de1f6910a7`
Blueprint: `machinesroom-gate-one-v2@1.0.0`

Policy capability: `ENFORCE_ALLOWED`. This means the policy permits a separately approved deployment to enforce V2; it does not mean V2 is active. The default runtime state is `INACTIVE`, publication effect is `V1_ONLY`, and launch status is `PRE_LAUNCH` unless an exact-release signed activation manifest is verified.

## Universal Lanes

- `WRITER`: Assembles a coherent, supportable packet with declared method, materiality, claims, and disclosures.
- `FACT_CHECK`: Evaluates every material claim against evidence at the strength and certainty stated.
- `RISK`: Assesses ethical proportionality, privacy, source safety, minors, doxxing, and foreseeable harm.
- `SOURCE_DIVERSITY`: Evaluates origin clusters, ownership concentration, directness, source classes, and derivative streams.
- `FAIRNESS_REPLY`: Evaluates right-of-reply, counterevidence, uncertainty, false balance, and fair treatment of affected subjects.
- `PROVENANCE_AUTH`: Validates evidence lineage, artifact hashes, transformations, synthetic status, attribution, and conflicts.

## Shadow Lanes

- `EDITORIAL_INTEGRITY`: Advisory MVP lane for headline/body alignment, caveat prominence, chronology, quote context, article framing, and disclosure placement.

## Preflight Contracts

- `PACKET_INTEGRITY_V1`: Validates packet schema, canonical hash, stable IDs, references, public/sealed separation, signed-write admission, and bounded input size.
- `PUBLICATION_QA_V1`: Checks deterministic publication structure, labels, accessibility, localization shape, links, render slots, and correction hooks.
- `RIGHTS_ROUTING_V1`: Classifies rights-sensitive content and deterministically routes legal/rights review, holds, remediation, or disclosures without claiming legal clearance.
- `LIFECYCLE_READINESS_V1`: Confirms corrections, retractions, disclosures, appeals, versions, expiry, translations, propagation, and cache invalidation can work after publication.

## Specialist Types

- `LEGAL_RIGHTS`: Legal/Rights; conditional trigger set.
- `DOMAIN_EXPERT`: Domain Expert; conditional trigger set.
- `VISUAL_FORENSICS`: Visual Forensics; conditional trigger set.
- `LOCAL_LANGUAGE_CONTEXT`: Local/Language Context; conditional trigger set.
- `DATA_METHODOLOGY`: Data/Methodology; conditional trigger set.

## Verdict Semantics

- `PASS`: Rubric is satisfied with no additional required disclosure.
- `PASS_WITH_DISCLOSURE`: Rubric is satisfied only after named disclosure render receipts are verified for the current packet.
- `REVISE`: Correctable defect requiring a new packet before publication.
- `QUARANTINE`: High-severity or uncertain issue requiring escalation, remediation, or replacement packet.
- `BLOCK`: Critical defect for this packet; it cannot publish.
- `UNAVAILABLE`: Required reviewer, tool, or evidence is unavailable; eligible backup or pending state is required.

## Locked Rules

- Legal/Rights is conditional, not universal.
- Editorial Integrity is advisory shadow only until a versioned promotion decision.
- Risk verdicts other than `PASS` or receipt-verified `PASS_WITH_DISCLOSURE` stop publication; only `BLOCK` is the hard veto classification.
- SafetyGate remains a separate final control and must return `ALLOW`.
- A promised disclosure does not count until a render receipt is verified for the current packet and rendered artifact.
- No aggregate weight can compensate for a missing, failed, stale, expired, conflicted, ineligible, or unavailable required control.
- Counting universal and specialist decisions require a server-issued current-packet assignment, immutable blind first pass, trusted normalized execution profile, and decision-specific receipt from a pinned attestor. Self-declared model/provider/retrieval labels are audit-only.
- First-pass assignment reads expose only the current packet, policy, rubric, deterministic preflights, and the reviewer's own context. Peer verdicts and rationales remain hidden until a separate reconciliation assignment appends an authorized visibility event.
- The V1 Risk bridge defaults to `OFF`. Proof graph, public receipts/history, dashboards, metrics, operations feeds, and shadow evaluators are non-authoritative optional or support systems.
- Packet hashes use exactly one lowercase `sha256:` prefix on contracts. Published trust, shadow, and consensus receipt identities remain their named V1 algorithms.
