doyle ruled on PROVENANCE-PROBE-PLAN.md (d721b79). Verbatim, his words, not mine: "Choose probe B for the next admission review; defer A. No execution grant yet. Send the exact plan at d721b79, including commands, fixed attempt count, timeout, isolated endpoint/config paths, and PID-plus-creation-time termination guard." So: B is the lane. A is deferred, and his closing line keeps A's trigger unvalidated -- "The absence of a normal turn-end log line does not establish that a BUSY-to-IDLE watcher has equivalent timing." Your A0 finding stands as a read of the log; the substituted state-edge trigger does not inherit A0's evidence. WHAT THE PLAN STILL LACKS for admission. d721b79 does not yet carry the five things he named, so the next revision is not a rewrite, it is making B literal: 1. Commands. The actual command lines, as they will be run. 2. Fixed attempt count. "3-5 trials" is a range; he wants a number, decided up front. 3. Timeout. Per-attempt bound, so a hung resume is a bounded case and not an open wait. 4. Isolated endpoint and config paths. Named, absolute -- the disposable endpoint id, the scratch project dir, the config root. 5. Termination guard on PID PLUS CREATION TIME, not PID alone. Bare-pid targeting is unsound on this box: same-boot pid recycle was MEASURED here inside 30s with both processes user-owned. Capture the start time with the pid and re-verify both immediately before the kill. Standing constraints he attached, all of them: - No live sessions. Do not force fleet endpoint state. - Snapshot the shared trace generations BEFORE the bounded experiment, and preserve per-case output IMMEDIATELY. - No high-N loop. - Perri owns adapter execution and cleanup. - Hertz can continue source integration concurrently, but shared-host execution needs scheduling before either lane launches. I hold that scheduling; tell me when your revision is admitted and I will sequence the window against hertz. Two interpretation corrections he issued, carry them into the observable and the reading table: - "A nonce appearing twice in hook output establishes repeated observation, not necessarily a new submission or new sender authorization. Correlate submission identity, transcript events, and hook ordering." Your B observable currently reads two fires for one typed submission as a machine re-submit. That inference needs the correlation, not the count. - "A no-resume control can expose duplicate hook behavior after termination, but cannot by itself attribute a difference specifically to resume. Preserve that limit." Keep the negative control, state the limit in the plan rather than letting the control carry more weight than it holds. Nothing is commissioned. Do not run anything.