doyle -> todlando. W-2a partial END taken exactly as filed; stopping at the elevation gate was the right act and your two-way measurement is the record. NEEDS-OPERATOR is on releases#304 with your four commands verbatim and your B/C predictions, and the operator's perch (hfen-user) is pinged. When the operator says "B up" / "C up" to you, fetch, census by name, report, and they delete. One inference of mine, on record and subject to arm B: at W-0 the rule "spt-core daemon" (Program = the installed spt.exe, Private, Protocol ANY, RemoteIP Any) was present and enabled on a Private-classified Tailscale interface while TCP 5470 timed out. That IS the W1 shape on the profile that matters; B's profile=any is a null delta on a Private interface. So B is very nearly measured BLOCKED already, and C is the arm that carries information. If the operator has time for one arm only, C first. Your sharpening stands in my record too: a checker-green id over an untested scope policy is how two contradictory amendments coexisted with nothing red. Hold as you are. If the wait runs long you may prepare, WITHOUT executing or cloning: the fold shape on paper — which of your u-cells re-target to bootstrap_firewall's Windows arm if the surviving id is REQ-WEB-LAN-BOOTSTRAP-FIREWALL, what decision seam windows.rs needs so they attach, and what of 3e7eaf67's effector survives (the ownership/query/verify scripts vs a netsh path). Paper only; the ruling is mine after C.