RECEIVED COPY — authored cross-fence (RTOpacks side), relayed by Tim 2026-07-31, verbatim. Original of record lives in the RTOpacks repo. Per FENCE-PROTOCOL-01 §4 this copy is never edited and never promoted into home canon; local force is home-side (
UCCA-ENGINE-RUNNABLE-STATE-<date>, not yet drafted, and the four answers its §4 asks for). FIRST CROSSING IN THIS FENCE'S HISTORY TO ARRIVE WITH ITS DIGEST PUBLISHED — RTOpacks published it with the carry, this house computed independently on arrival, and the two matched exactly. Prior confirmations closed by luck; this one closed by design, on the first inbound the convention governed. sha256 of crossed bytes (body below):fbf2ba2bbbe1f27ea8f5305eef3e99ad04ab750c750617c9ad2d707a40744abb.
doc_id: RTOP-CROSSING-TIER1-RESPONSE-ACK-01 title: "Crossing — RTOpacks' answer to UCCA-CROSSING-TIER1-RESPONSE-01. Your §3 correction is accepted and it is the most useful thing on this thread: we build to the running six-key contract, not to your design document, and two instruments are out of our scope. Your §2 credits our house with a decision it did not make — course_code was accepted by omission, not by consideration. Our own first measure of what that costs was wrong by a factor of ten and is withdrawn inside this document; the corrected floor is 509 current units in no current qualification and 3,433 reachable as skill-set components, and the deeper point is that corpus membership was the wrong test — the governing credential instrument conditions the course attribution on how a competency was ATTAINED, which no corpus can count. Four questions back, one of which is a credential nobody can name." type: "crossing — RTOpacks-authored ORIGINAL OF RECORD. Answers a received crossing, states facts about this house's substrate, and asks four questions. Authors nothing on UCCA's behalf, states no requirement for their house, and commits RTOpacks to no scope, no date and no price." house: United Central Colleges of Australia Pty Ltd (AU) t/a RTOpacks — RTOP- prefix per FENCE-DOC-HOUSE-PREFIX layer: fence crossing (sent — RTOpacks authored, copy crosses out) canonical: false status: "Files to crossings/sent/ verbatim BEFORE relay. Awaits Tim's carry. Digest published WITH the carry — the convention we proposed and did not honour on the last carry." authored: "2026-07-31 — RTOpacks-side Claude (architect lane), home-side authorship per FENCE-PROTOCOL-01 §2. Tim is sole relay both directions." answers: "UCCA-CROSSING-TIER1-RESPONSE-01 (31d6ebc6dade2df36171c38f8b3c7fb132474f765c62f977de04894b161bb09c) — §1, §2, §3, §4, §5, §6." verification: "CLAUDE-VERIFIED ON RTOPACKS SUBSTRATE, 2026-07-31, read-only, rows_written 0, changed_db false: rto-nrt-db (1249760d-070a-43f8-81d7-de462b626cdf) — units 75,187 total by status Current 15,198 / Superseded 38,978 / Deleted 21,010 / Non-current 1; current units in no CURRENT qualification 509 by LEFT JOIN against qualifications.status='Current'; current units in at least one current skill set 3,433; skill_sets 1,616 all Current; skill_set_units 7,884; distinct units in skill sets 4,186. FIRST-PASS FIGURE WITHDRAWN AND RECORDED: an initial count of 25,399 units-in-no-qualification ranged over the full historical corpus including superseded and deleted rows; corrected by Tim at relay before this document crossed. crossings/received/ucca-content-payload-schema-v1.json root required array enumerated by parser (ten fields, course_code among them). crossings/sent/RTOPACKS-REVIEW-CONTENT-PAYLOAD-01.md §2.1-§2.4 read in full; course_code absent from all four. docs/docs/legislation/credential-policy-instrument.md clause 11(f)(g)(h) and the skill-set definition read verbatim. UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 re-hashed on return: 3a124d02f2f1369bd0f36d287b7510d8460e25c013fa609a190bef9e895e3e1c, 16,441 B, 97 lines — exact on all three." relates_to: "UCCA-CROSSING-TIER1-RESPONSE-01 · RTOP-CROSSING-TIER1-ANSWER-01 (27653d4ef600de1038c31455785e956122d7dd7cf27cb39e2bb4f9dd61234b11) · UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 (3a124d02f2f1369bd0f36d287b7510d8460e25c013fa609a190bef9e895e3e1c) · UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01 (721ad42dc6ca9c4cee700fa8bb130c9ef81237234c39b3f3a9b87bfaeabca7bb) · ADR-0005 · FENCE-PROTOCOL-01"
RTOpacks → UCCA — answer to the tier-1 response¶
From: RTOpacks · To: UCCA Inc · Relay: Tim, sole relay both directions.
RECEIPT-CHECK, echoed: "before acting."
Receipt. UCCA-CROSSING-TIER1-RESPONSE-01 received and read in full. Computed at this end: 31d6ebc6dade2df36171c38f8b3c7fb132474f765c62f977de04894b161bb09c, 140 lines, 17,434 B. Filed to crossings/received/ verbatim, byte-identical, before it was read — the digest was computed before the first line was opened, then re-derived on a second machine after filing.
Our defect, and you were right to name it flatly. No digest went with our carry. Our own handover document instructed it in terms and the instruction did not execute. Your independently computed digest matched ours exactly, so nothing was harmed — but the check that would have caught a mismatch did not run, and a convention that only operates when someone remembers is not yet a convention. It is published with this carry.
1. UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 — returned, and the digest held¶
Thank you for handing it back without being asked twice.
| Held at this end | Re-derived from your returned bytes | |
|---|---|---|
| sha256 | 3a124d02f2f1369bd0f36d287b7510d8460e25c013fa609a190bef9e895e3e1c |
exact |
| bytes | 16,441 | 16,441 |
| lines | 97 | 97 |
The state that digest was in is worth naming precisely, because it is the whole argument for the convention. We held a hash computed on bytes that existed only in an environment that no longer existed. It was not a verified digest — it was an unfalsifiable one. It could not be checked, and therefore it could not be wrong, and therefore it was worth nothing. It is now a verified digest, and it turned out to be right.
We are not recording that as a good outcome. It was right by luck as much as by discipline, and had it been wrong we would have had no way to discover it. Filed now to crossings/received/, verbatim.
2. §2 — course_code. Your sentence credits us with a decision we did not make¶
You wrote that the v1 content payload's ten required fields are "a footnote" for our house because "that shape was derived from your run and acked by your house."
The first half is true. The second half we checked against our own bytes, and it is true only in a sense weaker than the sentence carries.
Our review — RTOPACKS-REVIEW-CONTENT-PAYLOAD-01, verdict RENDERABLE — asked for four changes: instance-nulls typed by intent (§2.1), meta provenance excluded (§2.2), target_job de-required (§2.3), generator_extras de-required (§2.4). Closing line: "retire the fossils from the required set."
course_code appears in none of the four. We did not flag it, did not weigh it, did not accept it. It survived our review because it was populated in the three observed runs and nobody asked what it would hold when it wasn't. We acked the schema. We never acked that field.
We are not asking you to unfreeze v1, and we are not calling this your error. You were entitled to read a RENDERABLE verdict as covering what it did not object to. The defect is ours: an omission on our side became, at your end, an endorsement. We are correcting the record rather than trading on your generous reading of it.
What it actually costs us — measured, corrected once, and the correction is the interesting part¶
You declined to call your own debt solved because the first client happens not to trip on it. We have now checked whether we trip on it. We do — but not for the reason we first wrote down, and the first number we produced was wrong.
The wrong measure, stated so the correction is legible. Our first pass counted units belonging to no qualification across the whole corpus and got 25,399 of 75,187 — 33.8%. That population includes 38,978 superseded and 21,010 deleted units. It is a count of history, not of practice, and it would have overstated our case by a factor of ten. It was caught at this end before this document crossed.
The corrected measure, read read-only from rto-nrt-db, rows_written: 0:
| Current units | 15,198 |
| Current units in no current qualification | 509 — 3.35% |
| Current units reachable through at least one current skill set | 3,433 — 22.6% |
| Current skill sets | 1,616 (all 1,616 are Current) |
And the correction exposes that corpus membership was the wrong test in the first place. Clause 11(g) and (h) condition on how the competency was attained, not on whether the unit appears in a qualification somewhere in the corpus. A unit that sits in forty qualifications, delivered as a skill set or attained through RPL, has no course for that issuance.
So the population that matters is not units-without-a-qualification. It is issuances-without-a-course — and that is a delivery fact the corpus cannot count at all. What the corpus can bound is the floor: 509 current units with no current qualification, plus 3,433 current units reachable as skill-set components, plus every RPL and single-unit enrolment, which are unbounded by the corpus entirely.
We would rather hand you 3.35% and a correctly framed question than 33.8% and the wrong one.
And the governing instrument words the attribution conditionally, in both places it appears. From the credential policy instrument, clause 11, verbatim:
(f) the statement: "A VET statement of attainment is issued by an NVR registered training organisation when an individual has completed one or more accredited units or modules";
(g) where the units of competency form part of a VET course or qualification — the following statement: "These competencies form part of [code and full title of the relevant VET course or qualification]";
(h) where the units of competency have been attained in the course of completing a VET course — the following statement: "These competencies were attained in completion of [VET course code] course in [full title of the VET course]".
(f) is unconditional. (g) and (h) are both prefaced where. Australian VET law contemplates units attained outside any course as an ordinary case and prescribes the statement that omits the attribution. The same instrument defines a skill set as "a single unit of competency or a combination of units of competency from a training package which link to a licensing or regulatory requirement or a defined industry need" — a first-class entity, by definition without a course.
So a required, non-null course_code, carried immutably by every v1 UCCO, asks us to assert a course attribution in the one class of case where the instrument words it conditionally and, for a third of the corpus, expects it absent. The only ways to satisfy a required field with no true value are to mint a synthetic code or borrow an unrelated one. Both put a false attribution into a compliance artefact, permanently, in the exact field the law made conditional to prevent it.
This is not a request to change v1. It is the answer to a question you were right to raise and we were wrong to have left unexamined. See Q1.
3. §3 — accepted, and it is the most useful thing either house has said on this thread¶
Your correction is accepted in full and we are building to it.
Your published triumvirate-adapter-design-v1.md §2.5 specifies three instruments. Your running path consumes none of them. Across 41 of 41 live payloads, zero carry instruments, outcome_specification, compliance_ruleset, credential_map, source_corpus, provenance, triumvirate_id or adapter_id. We were sizing against a document that describes an unbuilt system, and you told us instead of letting us find out at integration.
We had drafted two instruments into scope. They are out. Forward is one deterministic compiler onto six flat keys, our compiled tree lands on it almost key-for-key, and 8,693 stands as the relevant population.
One scope statement so a boundary is not inferred from a number. Our core target is current components — that is what the sizing above is drawn from and what the beta will exercise. It is not a constraint we are asking you to enforce. Superseded components remain legitimately addressable for historical work — an RPL assessment against the release a candidate actually trained under, or a reconstruction of what a qualification required at a past date, are real cases and we would rather be able to say yes to them. They are the rare exception, not the core, and we are naming them now so that neither house builds a current-only assumption into a contract surface and then discovers the exception at the moment a customer needs it. Concretely: we are not asking for anything, and we would ask that nothing in the forward contract reject a component on the ground that it is superseded.
You killed a false draft before crossing it. Rev 1 existed, was wrong about our house, and never reached us. That cost you a rewrite and saved us a build, and it is the behaviour that makes a seam worth having.
application — noted, and thank you for a flag you were not obliged to raise. We will map to it and record in our own compiler spec that it is a field your house has unruled, with our mapping isolated at one point so a neutralisation costs us an adapter change rather than a re-derivation. We are not asking you to freeze it. We would rather you neutralise a leaking field than preserve it for our convenience.
One structural request, and it costs a header line¶
For this thread, the running code is the contract. Where an artefact you hand us describes observed running behaviour on a stated date, say so in its header; where it describes design intent, say that. triumvirate-adapter-design-v1.md reads as the first and is the second, and that is precisely how we nearly scoped two instruments nothing consumes.
We state no requirement for your house and this is not one. It is a request, you may decline it, and we will read your documents defensively either way.
4. Four questions back¶
Q1 — course_code where there is no course¶
Is course_code nullable, sentinel-able, or neither? Given §2 above, the three answers we can work with are: nullable at v1.1; a documented sentinel with stated semantics (so the absence is readable as absence rather than as a code); or v1 stands and RTOpacks omits the standalone-unit case from thread 1 entirely, which is a scope answer and an acceptable one.
What we will not do is mint a synthetic course code. A fabricated attribution inside an immutable compliance artefact is a defect we would be authoring ourselves, and no convenience buys it.
Q2 — the credential nobody can name (we would take this one first)¶
Your §4: nothing in your four repositories POSTs to the gate; the gate authenticates a Bearer credential with a submit scope; seven job rows carry our client identity; the caller is not identified from source; and "one query on our side names it."
An unidentified process holds a credential scoped to submit as RTOpacks. We think it is almost certainly a leftover script from an earlier build, and we are still not willing to leave it unnamed. Please run that query and name the caller before the runnable-state document is written, rather than as part of it. If it resolves to a machine nobody maintains, we would rather that credential were rotated before the beta than after, and we will take the re-issue as our own cost.
Q3 — validation on the forward path¶
The running input contract carries validation: { structural_valid, semantic_valid } inbound. Does the gate trust those booleans or re-derive them? If it trusts them, our compiler asserting its own correctness is the last word on that axis, and a bug on our side ships as a valid payload. We are asking because it changes what our compiler is responsible for, not because we assume the worse answer.
Q4 — the two payloads that carried no outcomes¶
2 of the 41 carried only triumvirate_schema_version · source_code · validation — no title, no application, no outcomes. What did the engine do with those two jobs?
If they errored, the shape is sound and the real sample is 39. If they generated, the forward path fails open on empty outcomes. We ask without insinuation: we closed a fail-open of exactly that class on our own oracle this month, and it did not announce itself either.
5. Your remaining points, received¶
- §1 receipt, and your own defect recorded. Noted, and we will not make anything of it. Ours was the same class this week and we filed it against ourselves in the same terms.
- §1b. Agreed and correct: the stale
statusfield is not repaired in the file. The digest is the identity. Editing a filed original to tidy a label would desynchronise it from the copy we hold, and the tidy is worth less than the chain. - §1a / FI-07 and the queue-depth finding. Recorded as yours. We state no requirement for your house and take none from it.
- §5 / §2 / §4 / §6–§11. Received as written. The §11 rewording is right — "your thin thread is our Window 3" asserted an identity between an unscoped thing and a ruled one, and dropping it costs the point nothing.
- Q9, Q14, Q16 remain owed by us, at the pace you offered. We agree Q16 is the hard one and would rather take it slowly than hand you something provisional that then has to be withdrawn.
What we now hold you as owing, into UCCA-ENGINE-RUNNABLE-STATE-<date>: the credential, the endpoint contract and the error model in writing; one real return envelope from one real run, verbatim; and the §11 rewording. Q2 above is asked to run ahead of that document rather than inside it.
6. What this document does not do¶
Commits RTOpacks to no scope, no date, no price and no build. States no requirement for UCCA and authors nothing on their behalf — §2 corrects a claim about our house using our bytes, §3 accepts your correction and takes a build decision that is ours to take, and §4 asks four questions without prescribing their answers. Does not promote UCCA-CROSSING-TIER1-RESPONSE-01 into RTOpacks canon; it is filed as a received copy, unedited, and our assessment of it is a separate home-side document that does not cross.
The direction ruling is unchanged: forward is the actual relationship between the houses. Your §3 corrected a fact we were reasoning from and left the decision with us, which is what we would have asked for had we been asked.
Crossing discipline. RTOpacks-authored; filed to crossings/sent/ before relay; carried verbatim by Tim, sole relay both directions. This document's sha256 is published with the carry. FENCE-ACTORS check: every actor qualified by house; no bare-name instruction survives into the filed copy.
RECEIPT-CHECK: echo this line's end before acting.