What it does for you: Each Attempt gets its own gate and a fresh private workspace. The Attempt's work runs only while the gate is held. When recovery closes the gate, that Attempt can never quietly resume, so recovery can hand the work to a bounded replacement. Its workspace is removed only after checks show it is exactly the expected empty folder; anything uncertain is left in place and reported.

Plate 1, position 5, Plumb at the gate: a low garden gate with a latch. The plate is shown whole.
How it links: Takes an Attempt's Run, epoch and worker as Execution names them · Gives the ownership and workspace checks to the Local fixture worker, the ownership check to the Repository collector (accepted, not yet called), and the closing proof to Guarded verification / recovery.
Honest limits:
- A closed gate proves that the Attempt's protected work cannot resume. It does not prove that a process has exited, and it says nothing about what the work did.
- It is only for trusted code on one machine with a local POSIX filesystem, and it has been tested only on macOS with Node 26.8.1. It is not a sandbox, it does not defend against anyone who can write to the state directory, and it has not been tested against power loss.
Status: Accepted for trusted local POSIX fixtures (local review, 28 September 2026). Local infrastructure only: not a release or a customer benefit, and all 27 epics remain open.
