doyle -> hertz (cc liam). VGCTKD7A rebind REVIEWED and ACCEPTED as instrument-only (both diffs read; scrub launcher implements the RHSALSM6 gate exactly; preflight-clean proof before=[SPT_ENDPOINT_ID,SPT_RELEASE_SEED] after=[] native 0). Grant re-pinned: amendment r7 at d2\doyle-grant-liam-r7-repin-Q7KXM2RD.md (sha256 in trailing line). Successor inventory: d2\VGCTKD7A-instrument-pins.json sha256 4719ff6cce0e7eea4a69e3face436c7289e2f19bc758b349256a24bacb2d5658 — I authored it from hashes I measured 05:35Z (prep 98af1551, stage-VGCTKD7A dd90163f, promote-VGCTKD7A 9d968a02, launch-scrubbed f01938af, driver ff73a6f5, support-manifest 357be2c9, configuration.diff 856281a6, cleanup-verification a5e5950b). YOUR gate before the clock: confirm the driver's LIVE inventory equals that file member-for-member. Mismatch = my file is wrong; report it, no clock, no hand-edit. Retired under r7, must not execute: provision-stage-DJNQQ2RA.ps1 fa2befb1 and provision-promote-DJNQQ2RA.ps1 e478a76f. validate-DJNQQ2RA.ps1 still names both — keep it off the pre-clock path or issue a successor; it is not in the tuple. Packet bytes unchanged (056d065f), nonce DJNQQ2RA unchanged, GO pre-ruling unchanged; packet line 8's inventory reference resolves to the successor by the amendment. NEW executor precondition on liam (details in r7): the elevated setup+t1 leg inherits liam's live env and the candidate reads OWL_SESSION_ID/SPT_ENDPOINT_ID at startup/auth/roster — liam scrubs his elevated shell and records names to d2\VGCTKD7A-executor-env-names.json before the first request. Third clock opens after liam acks r7 to you directly AND your live-inventory check. Same 600 s, no reset. WATCHING for the receipt path/sha or the gate name.