What it does for you: It turns proposed text-file edits into a sealed Candidate: an exact commit and manifest that cannot quietly change afterwards. It exports those exact bytes in the form the Confined executor takes. When asked, it moves the target branch from the Candidate's base to its commit, at most once per prepared Action occurrence. If it cannot tell whether that move happened, it says "unknown". A caller can also hand it a last check that runs just before the move; if that check does not say yes, nothing moves, the call says "withheld", and that occurrence is used up.

Plate 2, positions 2 and 3: Plumb seals the parcel (Repository sealing / export), a parcel tied with string and a plain round seal, and Plumb at the points (Repository integration), a railway points lever. The plate is shown whole.
How it links: It takes proposed edits and pinned inputs from a caller, and canonical encoding from Command journal. Its exports fit the Confined executor; one test proves that run. Nothing in the Factory composes it yet. Deciding who may integrate belongs to the Product gate, which exists but is not yet joined to it.
Honest limits:
- It works only on fresh repositories it creates itself, on one Mac with Xcode's Git, in trusted local storage. It does not import existing projects or contact remotes.
- Not established: crash atomicity across its separate steps, surviving power loss, and protection from a hostile writer. An uncertain move stays "unknown", never "not applied", and "unknown" never permits a retry.
- The last check narrows the gap before the move but cannot close it: a change in the instant between the check and Git's own update is not seen. Nothing in the Factory passes such a check yet.
Status: Sealing / export is accepted for fresh owned local repositories. Integration is accepted as a local effect primitive. Both are local infrastructure only, not a release, a Verdict or a customer benefit, and all 27 epics remain open.
