# Evidence-backed coverage assessment v1 — STATIC/SYNTHETIC CONTRACT, NOT A SERVICE

This read-only example reports recorded metadata scope for a two-record synthetic footprint. It does not report or imply real-time service availability, answering, eligibility, capacity, safety, outcomes, quality, reachability, or universal geographic coverage.

The retained `source-evidence.synthetic.json` and `review-decision.synthetic.json` fixtures are conspicuously synthetic finite artifacts. Each retained observation structurally identifies its record, dimension, literal observation, and date. The adjacent terminal state is labeled a `reviewed_assertion`, but both it and the retained literal must equal an independent derivation from the exact released record bytes. The accepted review pins the exact source artifact SHA-256 and byte count plus the canonical digest of every evidence row; recomputing those internal pins cannot override released-record semantics. Provider or claimant assertions remain untrusted and cannot establish `observed` state or self-validate.

The counting unit is a footprint record. Every `(record_id, dimension)` pair has exactly one reviewed terminal state. For every dimension, `observed + unknown + not_observed + not_assessed = record_count`; the numerator is `observed`, while the denominator contains only assessed states (`observed`, `unknown`, and `not_observed`). Terminal dimension states are exhaustive: `not_assessed` means zero assessed rows; `partially_assessed` means assessed and unassessed rows coexist; for a fully assessed footprint, `unknown` means at least one indeterminate row, `observed` means every row was observed, `not_observed` means every row was not observed, and `mixed` means observed and not-observed rows coexist. Unrecognized field shapes conservatively derive `not_assessed`. These states report only bounded literal metadata observations and assessment footprint; they do not describe hotline availability, quality, completeness, recency, verification, trustworthiness, independent confirmation, or service coverage.

Validation also receives the exact generated `/api/v1/records.json` bytes, verifies its release/index digest and byte count, and compares the complete artifact with the exported production transformation, including exact keys, versions, and every record. Selected-record footprint checks remain separate and require the map key and released `id` to equal the evidence `record_id`. Exact predicates are: `channels` is present only for the exact `phone`/`text`/`chat` boolean object with at least one `true`, and absent when all are `false`; geography is present for a non-empty string and absent for an empty string; hours is present for a non-empty string and absent for `null` or an empty string; languages is present for a non-empty array of non-empty strings and absent for an empty array; field evidence is present for a non-empty released `sources` array of non-empty strings and absent for an empty array; recorded verification date is present only for a valid bounded calendar-date string and absent for `null`. Every other shape is `not_assessed`. `field_evidence` means only that bounded released `sources` field/value presence—not verified, trustworthy, current, available, or independently confirmed evidence. The JSON Schema fixes this artifact's two-record footprint and exhaustively enumerates every valid count/state partition for all six dimension positions; byte binding, transformation parity, and independent released-byte checks remain enforced by the trusted runtime validator and independent verifier.

Publication assumes a trusted worktree and a cooperative single writer enforced by the `O_EXCL` lock. Under that model, failure leaves no partial public directory. The generator covers malformed or untrusted artifact bytes, symlink boundaries, deterministic exposed test hooks, replacement before each final checkpoint, and writers that honor the lock. It keeps inode-pinned descriptors open and makes final validation the last userspace operation before path-based `renameSync`, with no await or production callback after that checkpoint. Node/macOS provides no atomic compare-inode-and-rename primitive, so arbitrary mutation by a non-cooperating same-UID process after the last check and before the rename system call is outside this guarantee.

There is no composite or weighted score, overall quality state, ranking, recommendation, provider comparison, hidden inference, write surface, intake, telemetry, outreach, pricing, billing, SLA, DPA, security, or commercial activation. Public files are exact-byte managed artifacts. SHA-256 detects byte mismatch after a descriptor is obtained through a trusted channel; it does not prove publisher identity or freshness.
