# Documental text-layer v3.1 operational evidence

Date: 2026-07-21

## Scope and provenance

This sanitized record covers the completed integrated-prototype live proof on branch
`feat/documental-extraction-v3.1` at implementation commit
`032b4d192007c67ed1e8dfe0d1d17c7f896cb09f`. The validated contracts were
`sibyla.extraction.v3.1` and `sibyla-documental/2.3`; the deployed plugin version was
`1.0.0`.

External sanitized evidence is retained outside the repository at
`D:\fileStorage\SibylaBackups\DeploymentEvidence\GOTT-Sibyla-v31-textlayer-e2e-20260721T062203Z.json`
with SHA-256
`8BF2032DA43FB5C89B3EA7DBB0547DCAB59C7DC49789074547B75E670BCAEEE8`.
Do not copy document text, party or sender identifiers, financial values, secrets,
or credentials into this repository.

## Validation and deployment proof

- Release build completed with 0 warnings and 0 errors; 235 .NET tests and 11
  plugin tests passed. An independent Codex review found no discrete code blockers.
- `GottSibylaWorker` was `Running` as `.\GottSibylaDocumental`; the effective owner
  suffix was `GottSibylaDocumental`.
- All 12 helper-manifest files and all 3 plugin-manifest files were validated.
- The plugin was enabled and its custom toolset was valid.
- A fresh plugin probe under the effective identity exited 0 without timeout and
  exposed no evidence in arguments, environment, stderr, or the restored runner.
  Its job root was removed.
- The focused Windows suspended-helper launch/EOF test under the same scheduled-task
  identity exited 0 without timeout, access error, or launch error. Its runner was
  restored and its job root was removed.
- No Application errors occurred after the post-deploy Worker restart. No transient
  helper or Hermes process was a descendant of the Worker.

## Sanitized end-to-end result

Document `0e46a3c2-3d17-4d06-81cc-d67a796a611f` used job
`8aef8546-2f88-4539-a1c2-1f0ff3f67d31`, which succeeded on its first attempt.
Revision 1 used Vision and revision 2 used Text. The result was `InvoiceReceipt`;
the document reached `AwaitingReview` and cataloging reached `NeedsReview` because
`known_direction`, `known_internal_company`, `known_counterparty`, and
`header_total` failed. An idempotent repeat returned the same existing job and kept
the revision count at 2.

All source-support booleans passed. There were zero `ExcelCommit`,
`FinancialAssessment`, `CegidCommit`, `CegidOperation`, integration jobs,
non-original assets, unexpected external writes, or retained job roots.

## Follow-ups and acceptance boundary

- Revision 2 is missing `SupersedesRevisionId`.
- Derived catalog and fingerprint audits reused the intake correlation instead of
  the reprocess correlation.

`[BLOCKED SECURITY]` This historical proof did not validate a parser security
boundary. The Worker now derives a `DISABLE_MAX_PRIVILEGE` token for helper launch,
but that is defense in depth: it retains the Worker's SIDs and integrity level and
does not establish filesystem or network isolation. Production remains blocked
until a complete least-privilege boundary is validated on the target host.
