No study yet: this module has no plate position.
What it does for you: It judges whether a sealed Candidate of a real repository did what its Slice promised. A Slice freezes the checks: the unchanged code must show the old behaviour, the Candidate the new one, and every guardrail must still hold. Each check is a run of one side's own files as the program over a fixed input, and it passes only on the pinned exit code. Output must match the pinned digest; this does not distinguish computed output from matching hard-coded or copied output. Before any Evidence counts, it confirms that the Candidate and its base are exactly the pinned ones. Each record must then come from the Evidence store unchanged, for this Attempt, on the pinned runtime, sandbox profile and limits, and within the time allowed. Every record tied to a check must be supplied. Anything else is set aside, so the result is Verified, Failed or Inconclusive and never better than the Evidence supports.
How it links: It takes sealed Candidate manifests from Repository, stored Evidence from Evidence / Assurance, written by the Repository collector, and the sandbox's snapshot format from the Confined executor. It gives repository Verdicts to the Product gate, which works each proof out again before a branch move, and to the delivery records, which judge the records again before measuring anything.
Honest limits:
- It is a pure judge: it runs nothing and stores nothing. The Repository collector that runs the checks is accepted too, but nothing calls either, so no real Slice has been judged; the tests judge store-written records, some from real sandboxed runs of test Candidates.
- Built-in test fixture Verdicts are never relabelled as repository Verdicts, and neither judge accepts the other's records.
- A proof is re-derivation over trusted local files, not cryptography: anyone who can write the Evidence store can forge. Review checks by a model are reserved and always Inconclusive.
Status: Accepted as step 1, increment 1, reviewed together with increment 2 (the Product gate): independent code review (Astra high) passed on 29 September 2026 in round 6, after rounds 1–5 each found something to fix (build review). Not composed into a delivery. This is local development only, not a release or a customer benefit, and all 27 epics remain open.
