SUPERVISED HANDOFF PROCEDURE WRITTEN, beside the driver and not inside it. No messaging infrastructure added to the driver, and v9 is byte-unchanged - I re-verified all six hashes after writing the file. HANDOFF-PROCEDURE-v9.md sha256 81dfb4d1e121a4357b7b01e863955bd30132f945262dcee8efbd2ff1df17fc5f 5103 bytes same directory as fp-driver-v9.sh (the 291081e5 session scratchpad). It adds no code and the driver does not consume it. Frozen set re-verified AFTER the write: driver a9510e1e, census 7a50b14e, cpubracket fc10031d, d1_render 3b984493, portfields 283386e7, runner-census 0d8b67ed. WHAT IT SPECIFIES, as you ruled it: The operator watches for HANDOFF_REQUESTED in findings.txt (or a new *-request.txt under $R/handoff/), knowing the 900s/300s clock is ALREADY RUNNING when that line appears - which is why this is the one step that cannot be left unattended. The operator sends liam the ABSOLUTE PATH and the NONCE, and nothing else. I wrote your reason in as the reason: the request file already holds the authoritative command and both capture paths, so a second copy in a message is a second source of truth that can disagree with the first. An ACK is required before delivery is relied on, with liam's own grounds stated (perch registration AUTH_REFUSED at SessionStart, reachable only through a separately-raised Monitor listener, tag bodies riding a leg that can swallow silently). No ACK means not delivered: re-send on the CLI channel, and if still no ACK treat liam as unreachable and STOP rather than let the clock expire. An ACK is a CURRENT availability check and not a guarantee - it says alive now and promises nothing about five minutes later, because liam's reachability dies with their session and a clear, compact or harness restart ends it with no signal on my side. The driver consumes the receipt itself. The operator never writes, touches, moves or pre-creates a receipt, and never runs the command; the nonce match is the driver's job and the operator's part ends at delivery. RE-CONFIRMATION, written as two checks rather than one, with your reason: once before the run, then AFTER the build and IMMEDIATELY BEFORE the firewall phase. A single check in front of a long cold build proves nothing about the phase that actually needs liam, because the build can outlive their session. The check belongs next to the thing it gates. A MISSING RECEIPT IS UNCERTAIN COMPLETION, and the document says so in those words: absence of a receipt is absence of a REPORT, never evidence of absence of an EFFECT. No re-issue of the command, no relaunch to try again - a blind retry of an elevated firewall mutation against an unknown state is how a field run creates the mess it exists to avoid. The $ST state markers and cleanup-failures.txt are the recovery instruction: read them, establish actual host state by census, bring it to you. After a cleanup-phase timeout, assume bootstrap-owned rules MAY REMAIN and say it in those words. Scope pre-granting is recorded as yours to do before admission, with liam's measured numbers as the justification rather than as a preference: 30-60s to a receipt with scope in hand (91s end to end including their own verification), 150s when a scope round trip is needed, against a 300s cleanup bound. YOUR OTHER POINTS: the runner/queue sample keeps its timestamp - registered runners read hfenduleam and kitsubito both status=online busy=false with ZERO queued and ZERO in_progress, sampled 2026-09-12 10:10Z, and it is recorded as the REMOTE availability view distinct from the local process axis. The analyzer-classification repair is hertz's and I am not touching it or proposing an edit to the frozen helper. No build, no field launch, nothing elevated, no product invocation. Outstanding on my side, unchanged: admission held; emphasys still offline on the #300 contract; the #300 submitter interpretation provisional pending Reavo via lia, with perri's co-authorship objection OPEN and the previous-commit interval not adopted; contract draft untouched at 24069979 and unpushed; the three register commits unpushed and the register unamended.