{
  "audit_date": "2026-07-20",
  "audit_disposition": "source_integrity_verified_runtime_enforcement_not_established_build_kit_verified_for_user_self_install",
  "build_kit_distribution": {
    "activation_contract": "user_initiated_read_only_preflight_then_exact_activation_card_approval",
    "bytes": 6818049,
    "install_on_download": false,
    "members": 116,
    "operational_data_authorized": false,
    "pre_install_disclosure_required": true,
    "readiness": "not_operational_build_required",
    "sha256": "c7efccc78b6947466f0e5c48cbd0f1321f9eeecc6ca0b0ce675c07dd4837c306",
    "supplied_name": "STEWARD-Hospital-Clinic-Administrator-Mission-Control-Hermes-Build-Kit-v1.0.0.zip",
    "target_application_version": "2.0.0"
  },
  "office_container_review": {
    "activex_found": false,
    "embedded_executable_or_ole_object_found": false,
    "external_relationship_found": false,
    "macro_or_vba_found": false
  },
  "public_distribution": {
    "activation_instructions_included": false,
    "complete_ai_os_claim": "paused",
    "executable_or_installer_included": false,
    "operational_data_authorized": false,
    "original_source_payload_included": false,
    "published_artifact_class": "non_executable_governance_preview"
  },
  "source_archive": {
    "bytes": 363602,
    "crc_passed": true,
    "internal_checksum_entries": 22,
    "internal_checksum_matches": 22,
    "members": 23,
    "path_or_member_safety_findings": 0,
    "sha256": "30d44b5372390318ce324d973d854a73a6aa840e889b2f960df4340d58ee2752",
    "supplied_name": "STEWARD-Hospital-Clinic-Administrator-Pack.zip"
  },
  "source_inventory": {
    "agent_declarations": 10,
    "agent_runtime_artifacts": 0,
    "component_files": 17,
    "declared_release_criteria": 160,
    "executable_schema_artifacts": 0,
    "power_declarations": 24,
    "schema_declarations": 18,
    "template_declarations": 30,
    "workflow_declarations": 24
  },
  "source_parity": {
    "embedded_components_matched": 17,
    "embedded_components_total": 17,
    "passed": true
  },
  "review_context": {
    "evidence_location": "Private local audit workspace plus public-safe derivative build-kit ZIP digest; preview alone is not runtime evidence",
    "publicly_reproducible_from_preview_alone": false,
    "review_type": "NAIO prepublication static source review; not third-party certification",
    "superseded_when": "Source archive digest, build-kit digest, preview artifacts, or review scope changes",
    "tooling_scope": "Local archive, checksum, container/XML, inventory, text-parity, and build-kit manifest checks"
  },
  "statement": "The original source archive was audited as untrusted input. Static source integrity and declaration inventories were verified. A newer Hermes functional build kit is distributed as an inert self-install ZIP for users to give their own Hermes. The public ZIP is a public-safe derivative of the verified kit with one synthetic MRN-like refusal-test fixture replaced by a non-person placeholder. Downloading, opening, or unzipping it installs nothing. Runtime enforcement remains not operational until a user's Hermes completes read-only preflight, presents an exact activation card, receives explicit approval, builds the target, and executes evidence-bearing tests. These provenance statements are not third-party certification, clinical validation, compliance assurance, or institutional authorization."
}
