# Decisions ## Evidence Reference Use `source_invocation_id + raw_path + evidence_excerpt` as the precise evidence reference for Executor claim bindings. Reason: - Invocation ID alone only identifies a tool call, not the evidence inside it. - `raw_path` is enough for the first version when paired with `retrieval_details.evidence_refs`. - `evidence_excerpt` remains the text Verifier reads, but only after Gatekeeper validates it. ## Raw Path Only support stable locators in the first version: - `$.alerts[i]` - `$.logs[i]` - `$.evidence_blocks[i]` No full JSONPath engine is introduced. ## Gatekeeper Severity Gatekeeper output includes: - `status` - `severity` - `checked_bindings` - `failed_rules` - `warnings` - `errors` Severity meaning: - `none`: precise references passed. - `low_confid`: evidence is missing or incomplete, but not fabricated. - `reject`: fabricated ID, wrong tool, unknown raw path, or mismatched excerpt. ## Verifier Boundary Verifier uses verified claim-local excerpts as primary derivability evidence. `tool_trace_summary` remains available for navigation and audit, but no longer needs to carry every concrete fact. ## Hook Placement Gatekeeper remains in the Verifier input hook path. This version does not retry Executor on Gatekeeper failure. ## Planner Planner is not changed. `scope_contract` remains a later-stage idea. This phase uses prompt constraints to reduce narrow-scope over-expansion. ## Database No new tables. Evidence refs are stored in `tool_invocation.retrieval_details.evidence_refs`; audit is stored in `diagnosis_session.self_evaluation.verifier_evaluation.gatekeeper_result`.