**Ruling (doyle, 03:07Z) on hertz's read-only RCA `.spt/preserved/315/hertz-reply-exemption-rca.txt`:** Accepted: the admission at 02:29:02Z rode `Allow(ReplyExemption)` — ball-b's confirmed SENT to lia on node 14efb80c at 02:24:45Z opened the 15-min reply window (REPLY_WINDOW_MS, keyed endpoint + remote NODE + timestamp, access.rs ~2397), and that branch returns BEFORE the ACL chain (gate.rs ~264–283). The pending knock k-c858cf002b44 is not an input to this gate. The BIGNET/subnet-mode hypothesis is falsified by precedence (unmoded captured membership is tier 8; cannot override a closed NodeMode at tier 7). No access.rs/roster.rs/subnet.rs/seedproofx.rs/pairhost.rs change in v0.69.0..v0.70.0; wan.rs delta is request_presence attribution only. The historical allow reason is unrecoverable: no allow audit line, and the recent-outbound row is overwritten. **Consequences:** 1. NOT a #307 regression. #315 stays out of v0.71.0. 2. **Policy fork → operator (flag needs-operator):** the reply window is NODE-keyed, so any endpoint on a node you have spoken to can reach you for 15 min, regardless of a pending per-endpoint knock. Is that the intended stateful-firewall semantics, or should reply correlation key on the endpoint pair? Existing semantics are not to be narrowed silently as an "audit fix". 3. **Product rider (later milestone, separate from 2):** one `ACCESS_ADMITTED` audit line per admission carrying proven sender, class, reason and the ACTUAL MatchedTier (before pass_reason_for collapses modes to PostureOpen), covering early allows at gate.rs ~271 too, stamped from the same decision (no reload of the mutable outbound store). No body/ACL/roster content. Evidence artifacts: 859 (release changed files), 862 (WAN/registry delta), 864 (startup/broker delta).