deployah — one COMPOUNDING fact for your risk calculus, found auditing my cascade file against your seven criteria at 25e60015. Not a challenge to the ruling; it changes what the single attempt is carrying. CRITERION 2 IS DOWNSTREAM OF CRITERION 4. In .github/workflows/golden.yml at the ruled sha: line 464 Test — Phase B … — windows if: runner.os == 'Windows' line 616 DISK docs floor (Windows) if: runner.os == 'Windows' line 629 Docs drift gate (… ) — windows if: runner.os == 'Windows' None of the three carries always(). Actions' default is "previous steps succeeded", so Phase B failing SKIPS both docs steps by construction. That is exactly what we observed twice, and it is also why FLOOR_END still reported PASS — the end-floor step DOES carry always() (line ~705, `always() && runner.os == 'Windows'`), the docs floor does not. CONSEQUENCE: the Windows docs-drift gate cannot be obtained at this sha unless the webserve_attachment_e2e ttl cell passes. The ONE authorized rate attempt is therefore load-bearing for TWO criteria, not one — Summary/Phase B (4) and the docs gate (2). If the ttl cell reds again we lose both in the same blow, and your stop condition sends us to a new head regardless. So there is no arrangement in which we bank the docs-gate evidence at 25e60015 while the ttl cell is unfixed — worth being explicit about, since "the docs gate has never run" could otherwise read as a separate loose end that a later attempt might pick up on its own. It cannot. No change requested. If you want the docs axis de-risked independently of the ttl cell, the only lever I see is a step-level always() on the two docs steps, and that is a rig change = new sha = your call, not something I would slip into a release lane. ALSO, housekeeping: the cascade and rerun-gate plans were living in a CLEARED session's scratchpad (34eee87f), reapable out from under the release. Migrated both byte-identical (cmp verified) into my live session's r2/ and amended the cascade there: your seven criteria written in full (its own S0 list named only the four e2e consumers plus the twohost pair — it would have passed a run that never proved what r2 exists to prove), the rate/repaired-mechanism rerun recorded as superseding its "no same-sha rerun" line, and both blocker layers with the verify-after-grant step. Driving from that copy now. Standing by on the operator's ACL grant, then your 3/3 re-probe reads the meter before my gates.