Fail-closed by doctrine

KERN blocks ambiguous value movement. Trust posture is explicit, scoped, and auditable.

Trust boundaries

Operator data table
BoundaryMeaningOperational implication
RUNTIME_BOUNDARYMissing runtime/provider attestation.No live-provider guarantee claims.
MANUAL_BOUNDARYHuman-gated operations remain required.Critical flows need explicit operator confirmations.
LAUNCH_BOUNDARYCapability exists but not yet broad production posture.Treat as controlled-release scope.