# Eve end-to-end data inventory and flow map

Task 14.1 inventory dated 2026-09-15. It covers 12 source-verified planes × 9
modalities = 108 explicit cells, with 45 flows and 63 fail-closed non-flows.

“FLOW” means payload or a stated minimized projection crosses the plane. It does
not mean every downstream privacy control is complete. Each JSON flow cell
carries the full required fields and all six destination dispositions.

| Plane                 | `text` | `structured-record` | `document-pdf` | `image-screenshot` | `audio` | `video` | `code` | `three-d-scene` | `telemetry-evidence` |
| --------------------- | ------ | ------------------- | -------------- | ------------------ | ------- | ------- | ------ | --------------- | -------------------- |
| `session-http`        | FLOW   | FLOW                | —              | —                  | —       | —       | —      | —               | FLOW                 |
| `operator-http`       | FLOW   | FLOW                | —              | —                  | —       | —       | —      | —               | FLOW                 |
| `prompt-assembly`     | FLOW   | FLOW                | FLOW           | —                  | —       | —       | FLOW   | —               | FLOW                 |
| `member-domain-tools` | FLOW   | FLOW                | —              | —                  | —       | —       | —      | —               | —                    |
| `client-tool-bridge`  | FLOW   | FLOW                | —              | FLOW               | —       | —       | —      | —               | —                    |
| `retrieval`           | FLOW   | FLOW                | FLOW           | —                  | —       | —       | —      | —               | —                    |
| `operator-tools`      | FLOW   | FLOW                | —              | —                  | —       | —       | —      | —               | FLOW                 |
| `memory-and-session`  | FLOW   | FLOW                | —              | —                  | —       | —       | —      | —               | —                    |
| `workbench-intent`    | FLOW   | FLOW                | FLOW           | FLOW               | FLOW    | FLOW    | FLOW   | FLOW            | FLOW                 |
| `model-provider`      | FLOW   | FLOW                | FLOW           | FLOW               | FLOW    | —       | FLOW   | —               | FLOW                 |
| `voice`               | FLOW   | —                   | —              | —                  | FLOW    | —       | —      | —               | —                    |
| `audit-and-evidence`  | FLOW   | FLOW                | —              | —                  | —       | —       | —      | —               | FLOW                 |

## Open requirements exposed by the inventory

| Cell                                    | Field                                                           | Owner task | Exact condition                                                                                                                             |
| --------------------------------------- | --------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `audit-and-evidence/structured-record`  | `deletion`                                                      | `14.4`     | Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained.                       |
| `audit-and-evidence/structured-record`  | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer.                             |
| `audit-and-evidence/structured-record`  | `retention`                                                     | `14.5`     | Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5.                                              |
| `audit-and-evidence/telemetry-evidence` | `deletion`                                                      | `14.4`     | Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained.                       |
| `audit-and-evidence/telemetry-evidence` | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer.                             |
| `audit-and-evidence/telemetry-evidence` | `retention`                                                     | `14.5`     | Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5.                                              |
| `audit-and-evidence/text`               | `deletion`                                                      | `14.4`     | Task 13.6 verifies measured subject-audit deletion; minimized non-subject release evidence is intentionally retained.                       |
| `audit-and-evidence/text`               | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for audit-and-evidence must be admitted before transfer.                             |
| `audit-and-evidence/text`               | `retention`                                                     | `14.5`     | Audit and evidence schedules, access, exceptions, and tamper-evidence policy remain Task 14.5.                                              |
| `client-tool-bridge/image-screenshot`   | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer.                             |
| `client-tool-bridge/structured-record`  | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer.                             |
| `client-tool-bridge/text`               | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for client-tool-bridge must be admitted before transfer.                             |
| `member-domain-tools/structured-record` | `deletion`                                                      | `14.4`     | Covered V1 subject stores join deletion fanout; total domain and artifact propagation is Task 14.4.                                         |
| `member-domain-tools/structured-record` | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for member-domain-tools must be admitted before transfer.                            |
| `member-domain-tools/structured-record` | `retention`                                                     | `14.5`     | Retention belongs to each domain store and is not yet joined into one enforceable policy.                                                   |
| `member-domain-tools/text`              | `deletion`                                                      | `14.4`     | Covered V1 subject stores join deletion fanout; total domain and artifact propagation is Task 14.4.                                         |
| `member-domain-tools/text`              | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for member-domain-tools must be admitted before transfer.                            |
| `member-domain-tools/text`              | `retention`                                                     | `14.5`     | Retention belongs to each domain store and is not yet joined into one enforceable policy.                                                   |
| `memory-and-session/structured-record`  | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for memory-and-session must be admitted before transfer.                             |
| `memory-and-session/structured-record`  | `retention`                                                     | `14.5`     | Expiry/salience metadata exists for operator memory; a total operator-visible retention policy remains Task 14.5.                           |
| `memory-and-session/text`               | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for memory-and-session must be admitted before transfer.                             |
| `memory-and-session/text`               | `retention`                                                     | `14.5`     | Expiry/salience metadata exists for operator memory; a total operator-visible retention policy remains Task 14.5.                           |
| `model-provider/audio`                  | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/audio`                  | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying audio.                                                           |
| `model-provider/audio`                  | `modelLeg:speech-to-text`                                       | `14.2`     | The speech-to-text leg has no independently verified provider storage, retention, training, residency, or subprocessor record.              |
| `model-provider/audio`                  | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/audio`                  | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/code`                   | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/code`                   | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying code.                                                            |
| `model-provider/code`                   | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/code`                   | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/document-pdf`           | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/document-pdf`           | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying document-pdf.                                                    |
| `model-provider/document-pdf`           | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/document-pdf`           | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/image-screenshot`       | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/image-screenshot`       | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying image-screenshot.                                                |
| `model-provider/image-screenshot`       | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/image-screenshot`       | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/structured-record`      | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/structured-record`      | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying structured-record.                                               |
| `model-provider/structured-record`      | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/structured-record`      | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/telemetry-evidence`     | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/telemetry-evidence`     | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying telemetry-evidence.                                              |
| `model-provider/telemetry-evidence`     | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/telemetry-evidence`     | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/text`                   | `deletion`                                                      | `14.4`     | No provider-side deletion proof is claimed; Task 14.2 must establish terms and Task 14.4 must bind propagation.                             |
| `model-provider/text`                   | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for every model leg carrying text.                                                            |
| `model-provider/text`                   | `modelLeg:computer-use-planning`                                | `14.2`     | The computer-use-planning leg has no independently verified provider storage, retention, training, residency, or subprocessor record.       |
| `model-provider/text`                   | `modelLeg:embedding`                                            | `14.2`     | The embedding leg has no independently verified provider storage, retention, training, residency, or subprocessor record.                   |
| `model-provider/text`                   | `modelLeg:escalation`                                           | `14.2`     | The escalation leg has no independently verified provider storage, retention, training, residency, or subprocessor record.                  |
| `model-provider/text`                   | `modelLeg:judge`                                                | `14.2`     | The judge leg has no independently verified provider storage, retention, training, residency, or subprocessor record.                       |
| `model-provider/text`                   | `modelLeg:text-to-speech`                                       | `14.2`     | The text-to-speech leg has no independently verified provider storage, retention, training, residency, or subprocessor record.              |
| `model-provider/text`                   | `modelLeg:turn`                                                 | `14.2`     | The turn leg has no independently verified provider storage, retention, training, residency, or subprocessor record.                        |
| `model-provider/text`                   | `modelLeg:vision`                                               | `14.2`     | The vision leg has no independently verified provider storage, retention, training, residency, or subprocessor record.                      |
| `model-provider/text`                   | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `model-provider/text`                   | `retention`                                                     | `14.5`     | Routing filters are measured, but provider practice and subprocessors are explicitly unverified until Task 14.2.                            |
| `model-provider/text`                   | `upstreamSource:apps/oshun/bff/src/assistant/model-registry.ts` | `15.1`     | Refresh the model-leg contract's nested binding for apps/oshun/bff/src/assistant/model-registry.ts before using it as current source proof. |
| `operator-http/structured-record`       | `deletion`                                                      | `14.4`     | Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work.                 |
| `operator-http/structured-record`       | `retention`                                                     | `14.5`     | The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions.                                                |
| `operator-http/telemetry-evidence`      | `deletion`                                                      | `14.4`     | Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work.                 |
| `operator-http/telemetry-evidence`      | `retention`                                                     | `14.5`     | The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions.                                                |
| `operator-http/text`                    | `deletion`                                                      | `14.4`     | Subject-bearing stores join the deletion fanout, while compliance retention and legal-hold conflicts remain Task 14.4 work.                 |
| `operator-http/text`                    | `retention`                                                     | `14.5`     | The underlying stores have mixed policies; Task 14.5 must totalize durations and exceptions.                                                |
| `operator-tools/structured-record`      | `deletion`                                                      | `14.4`     | Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4.                      |
| `operator-tools/structured-record`      | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer.                                 |
| `operator-tools/structured-record`      | `retention`                                                     | `14.5`     | Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable.                                    |
| `operator-tools/telemetry-evidence`     | `deletion`                                                      | `14.4`     | Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4.                      |
| `operator-tools/telemetry-evidence`     | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer.                                 |
| `operator-tools/telemetry-evidence`     | `retention`                                                     | `14.5`     | Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable.                                    |
| `operator-tools/text`                   | `deletion`                                                      | `14.4`     | Rights and subject-bearing paths exist, but complete cross-domain and retained-audit reconciliation remains Task 14.4.                      |
| `operator-tools/text`                   | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for operator-tools must be admitted before transfer.                                 |
| `operator-tools/text`                   | `retention`                                                     | `14.5`     | Retention belongs to the underlying operational stores; Task 14.5 must make it explicit and inspectable.                                    |
| `prompt-assembly/code`                  | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.                                |
| `prompt-assembly/document-pdf`          | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.                                |
| `prompt-assembly/structured-record`     | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.                                |
| `prompt-assembly/telemetry-evidence`    | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.                                |
| `prompt-assembly/text`                  | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for prompt-assembly must be admitted before transfer.                                |
| `retrieval/document-pdf`                | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer.                                      |
| `retrieval/structured-record`           | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer.                                      |
| `retrieval/text`                        | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for retrieval must be admitted before transfer.                                      |
| `session-http/structured-record`        | `retention`                                                     | `14.5`     | No duration is enforced at this plane; Task 14.5 owns the policy.                                                                           |
| `session-http/telemetry-evidence`       | `retention`                                                     | `14.5`     | No duration is enforced at this plane; Task 14.5 owns the policy.                                                                           |
| `session-http/text`                     | `retention`                                                     | `14.5`     | No duration is enforced at this plane; Task 14.5 owns the policy.                                                                           |
| `voice/audio`                           | `deletion`                                                      | `14.4`     | No durable local raw-audio store is admitted; provider-side lifecycle remains unproved.                                                     |
| `voice/audio`                           | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for the voice audio route.                                                                    |
| `voice/audio`                           | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `voice/audio`                           | `retention`                                                     | `14.5`     | Local buffers are request-scoped, but provider retention is unmeasured and owned by Task 14.2.                                              |
| `voice/text`                            | `deletion`                                                      | `14.4`     | No durable local raw-audio store is admitted; provider-side lifecycle remains unproved.                                                     |
| `voice/text`                            | `destination:storage`                                           | `14.2`     | Establish provider-side storage and buffering for the voice text route.                                                                     |
| `voice/text`                            | `providerTransfer`                                              | `14.2`     | Routing enforcement is recorded, but provider practice and subprocessors require independent review.                                        |
| `voice/text`                            | `retention`                                                     | `14.5`     | Local buffers are request-scoped, but provider retention is unmeasured and owned by Task 14.2.                                              |
| `workbench-intent/audio`                | `deletion`                                                      | `14.4`     | Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.         |
| `workbench-intent/audio`                | `destination:artifact`                                          | `14.4`     | Register the owning audio artifact store, owner, identity mapping, and deletion propagation path.                                           |
| `workbench-intent/audio`                | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/audio`                | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/code`                 | `deletion`                                                      | `14.4`     | Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.         |
| `workbench-intent/code`                 | `destination:artifact`                                          | `14.4`     | Register the owning code artifact store, owner, identity mapping, and deletion propagation path.                                            |
| `workbench-intent/code`                 | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/code`                 | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/document-pdf`         | `deletion`                                                      | `14.4`     | Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.         |
| `workbench-intent/document-pdf`         | `destination:artifact`                                          | `14.4`     | Register the owning document-pdf artifact store, owner, identity mapping, and deletion propagation path.                                    |
| `workbench-intent/document-pdf`         | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/document-pdf`         | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/image-screenshot`     | `deletion`                                                      | `14.4`     | Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.         |
| `workbench-intent/image-screenshot`     | `destination:artifact`                                          | `14.4`     | Register the owning image-screenshot artifact store, owner, identity mapping, and deletion propagation path.                                |
| `workbench-intent/image-screenshot`     | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/image-screenshot`     | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/structured-record`    | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/structured-record`    | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/telemetry-evidence`   | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/telemetry-evidence`   | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/text`                 | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/text`                 | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/three-d-scene`        | `deletion`                                                      | `14.4`     | Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.         |
| `workbench-intent/three-d-scene`        | `destination:artifact`                                          | `14.4`     | Register the owning three-d-scene artifact store, owner, identity mapping, and deletion propagation path.                                   |
| `workbench-intent/three-d-scene`        | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/three-d-scene`        | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |
| `workbench-intent/video`                | `deletion`                                                      | `14.4`     | Task 13.6 verifies deletion of PostgreSQL workbench metadata references only; owning binary stores are unregistered and unverified.         |
| `workbench-intent/video`                | `destination:artifact`                                          | `14.4`     | Register the owning video artifact store, owner, identity mapping, and deletion propagation path.                                           |
| `workbench-intent/video`                | `providerTransfer`                                              | `14.2`     | Provider identity, terms, residency, and subprocessors for workbench-intent must be admitted before transfer.                               |
| `workbench-intent/video`                | `retention`                                                     | `14.5`     | Work records, immutable events, and artifact references need explicit class-specific schedules in Task 14.5.                                |

## Integrity and scope

Record digest:
`6820699cfc49fbe2a1fc01069c20b19d570399b81e6bd77c792d2218ac057b75`.

- Every Task 4.1 plane and every admitted modality intersect in exactly one
  explicit flow or not-applicable cell.
- Every flow records source, purpose, actor/tenant binding, classification,
  prompt and provider transfer, all six destination kinds, retention, deletion,
  and owner.
- Every flow cell participates in at least one typed edge, and every admitted
  model leg maps to concrete transfer cells, provider targets, and source-bound
  implementation references.
- Unknown or partial lifecycle facts remain open requirements with a named owner
  task; they never default to absent, safe, or complete.
- A stale nested source digest in an upstream authority is exposed as an owned
  discrepancy while the current runtime file is bound directly.
- Cross-plane edges may narrow authority and classification but may not widen
  either.
- A new plane, modality, provider leg, destination kind, or source binding
  invalidates this inventory until regenerated and reviewed.

## Limitations

- This is a source-bound inventory and flow map, not proof that every listed
  retention, deletion, minimization, or provider control is deployed.
- Task 14.2 owns provider and subprocessor practice; Task 14.3 owns end-to-end
  minimization; Task 14.4 owns complete rights propagation; Task 14.5 owns
  retention and audited access; Task 14.7 owns creative-media licence and
  consent.
- Artifact modalities on the workbench plane describe manifests and references,
  not an assertion that raw binary payloads are stored in PostgreSQL.
- The unregistered artifact-custody endpoint is an explicit inventory gap, not a
  claim that its store, owner, retention, or deletion behavior is known.
- Media generation, video understanding, and 3D provider legs remain unadmitted;
  their cells stay explicit not-applicable entries rather than disappearing.
- Task 13.6 recovery results are local measured evidence for eleven families and
  do not prove production backup, provider deletion, or legal compliance.
- The Task 15.1 model-leg record has a stale nested model-registry source
  digest; Task 14.1 binds the current file and exposes the discrepancy rather
  than silently treating the older digest as fresh.
