GMAA Governed Multi-Agent Architecture
Engine package v2.5.7 · canon pin v1.6.1

The GMAA Engine Map

How the engine implements the specification. Engine package v2.5.7 · canon pin v1.6.1 · cite by version. Canonical home: gmaa.ai. Verification fingerprints for the release are on gmaa.ai/versions.html.

Who this is for. Anyone evaluating GMAA for a project, and anyone who has downloaded the engine and wants the map before the tree. The specification states the law; the engine is the machinery that enforces it. Reading the law alone answers "what must hold" but not "what runs, what fires it, and what it costs to operate," and an evaluation made on the law alone tends to overprice the discipline and misread designed absences as gaps. This document is the missing middle: every file in the release, grouped into ten functional areas, each anchored to its canon section, with the execution wiring that shows what invokes what and when.

Three facts an evaluation can miss reading the specification alone. First, the engine creates its own repository at instantiation: no prior version control is required, and an ungoverned workspace is the starting condition adoption is designed for, not a blocker to it. Second, empty substrate slots are a designed posture, not gaps: a project with no database, no API, and no side-effectful backend leaves the C-DB and C-GATE slots unfilled, and SLOTS.md is the inventory of exactly those decisions. Third, the discipline is wired, not manual: hooks fire at every commit, a guard fires on every shell call, probes run on schedule, and seat files are generated rather than maintained, so the recurring human act is one ratification decision per set, and that decision is the product rather than the overhead.

Method. The canon (v1.6.1, all sections) was read whole, then every one of the 102 files in the package plus the 4 loose release files beside the zip was inventoried and its header, purpose block, or full body read. Every file is assigned to exactly one functional area below; a coverage account at the foot proves nothing was orphaned. Where a file is machinery, the map states what invokes it and when it fires, because a gate is defined as much by its trigger as by its logic.

The shape of the whole thing in one paragraph. The canon states one correction: authorize the set, not only the change, with an integrator agent assessing and an independent human ratifying. The engine implements that correction as ten cooperating layers: an identity layer that makes a seat something you derive rather than assert; a single-writer enforcement layer that makes the spine physically uncommittable by anyone but foundation; the set-authorization machinery itself, which is the thesis in executable form; a work lifecycle that moves a change from dispatch to independently audited closure; a merge and reap layer that keeps worktrees honest; a relay layer that keeps transport off the participants; a standing audit layer that probes invariants instead of asserting them; an instantiation and upgrade layer that turns the blank template into a project and keeps it upgradeable; the harness wiring that makes the runtime itself enforce the above; and the release integrity envelope around all of it.


1 The specification layer, the law everything below implements

Canon anchor: the whole document.

FileRole
canon/GOVERNED_MULTI_AGENT_ARCHITECTURE_v1_6_1_PUBLIC.mdThe specification, carried in-zip so every adopter holds the exact law their engine version conforms to. CC BY 4.0, licensed separately from the engine. Nothing executes it; everything below is checked against it, and the set assessment (§4, §10) can find a set in conflict with any part of it.

The canon's own instantiation checklist (§12) is the adopter's entry point into it; section 9 below carries the files that walk it.

2 Identity and the seat lifecycle

Canon anchors: §1.0 definitions, §1.1 seats and surfaces, §2 ONE-SESSION-ONE-SEAT, §7.1 Boot-0, §7.2 provisioning, §7.3 project-qualified identity.

The design law of this area: identity comes from location, is derived on both sides of the spawn boundary, and the two derivations must agree or the seat halts. A hand-made folder cannot mint a seat because it has no committed stamp.

FileWhat it is and what runs it
_boot/BOOTSTRAP.mdThe stamp: project, lane, session name, branch, fixed at provisioning. Read at boot by the launcher and the resolver; never asserted at runtime.
_boot/CHARTER-foundation.md, _boot/CHARTER-executor.mdThe two shipped seat charters, read at Boot-0 step 7, authored before the seat exists per charter-precedes-boot.
scripts/resolve-lane.shThe shared identity resolver: lane = worktree folder name, cross-checked against the stamp, halt on mismatch. Consumed by cold-boot, the pre-commit hook, and the post-commit hook, so commit-time enforcement keys on the same identity boot does.
scripts/resolve-project.shThe §7.3 project-token resolver: reads the stamped project: field, composes {project}-{lane} for the tmux namespace, never guesses.
launch-orc.shThe one launcher, identical bytes in every worktree. Resolves lane from the stamp, refuses double-launch on the exact qualified session name, creates the named tmux session, sends the launch line, prints an observed-facts receipt.
scripts/orc-up.shThe two-word operator wrapper over the launch path: fail-closed bootstrap check, named session at the lane worktree, claude --agent orc.
scripts/orc-restart.shThe §7.4 remedy made cheap: checkpoint first, kill, orc-up. Restart over degraded continuation.
scripts/boot-check.shThe boot-discipline presence and currency gate, one script for all lanes. Fired two ways: called from each lane's bootstrap, and wired into the harness SessionStart hook so presence is harness-enforced rather than agent willpower.
scripts/preflight.shThe substrate floor made testable: checks Claude Code CLI, git with auth, tmux, and that every shipped agent definition leads with loadable frontmatter. Reports and halts; provisions nothing, per the floor ruling.
CLAUDE.mdThe condensed hot operating surface every session loads: cold-boot identity, the B6 context lifecycle, the binding invariant shapes, seat topology, slot pointers.

The agent-definition roster (.claude/agents/), canon §1.0 "agent definition" and §1.3 subagent classes. These are the qualifications a session loads to become a fit occupant:

DefinitionClass and boundary
orc.mdThe role-neutral orchestrator seat definition; the folder it launches in resolves whether it is foundation (spine write ALLOW) or a module lane (DENY). The one definition that is a seat, not a subagent.
architect.mdThe optional code-resident architect seat: reads everything at HEAD read-only, ratifies HOW-class, writes exactly one territory (its drop-zone), never commits, never executes mechanisms.
build-worker.mdBuilder class: one work package per spawn, own branch, emits artifact plus probe plus receipt, closure deferred to the independent audit.
dispatch-executor.mdAdvancing-executor class: runs dispatch files pass by pass, surfaces ratification checkpoints, never strategizes.
docs-resolver.mdRead-only prober for live external documentation; returns verbatim content with source citations, per discipline rule 3.
general-purpose.mdBounded fan-out worker for foundation: authoring-only by default, never commits, halts loud on ambiguity.
canvas-monitor.mdRead-only drift monitor over canvas-surface outputs, spawned on a logged event, never modifies what it watches.

One file in this area is deliberately absent: seats.yaml is not shipped. It is the adopter's roster and spine-path declaration, created at instantiation (SLOTS.md row 49), spine-owned and set-gated once it exists, and read at HEAD by the enforcement layer below.

3 Single-writer enforcement and spine protection

Canon anchors: §1.1 single-writer invariant, §8 permission architecture, Appendix A wrong-authorization-unit and FIX-SURFACE-DIVERGENCE.

This area answers one question mechanically: can anyone but foundation land bytes on the spine? The answer is layered so that no single bypass defeats it.

FileWhat it is and what runs it
scripts/spine-census.shThe single authoritative emitter of what counts as a protected spine path, one path per line. The v2.5.6 fix: every enforcement consumer reads its census from here, ending the hand-copied-census drift that let a merge-time gate miss the set-authorization machinery's own files. Consumers: the pre-commit hook, reap_at_merge.sh, ratify.sh, probe_state_propagation.sh, probe_set_gate.sh.
scripts/declared-spine-paths.shThe adopter's extension of the census: reads spine_paths: from seats.yaml at HEAD (git show HEAD:seats.yaml), never the working tree, so a lane cannot forge its own roster to widen its own exemptions.
agents/pre-commit-hook.shThe D3 hard gate, canonical source for .git/hooks/pre-commit: resolves the committing lane, reads the census plus declared paths, blocks a module or executor commit touching any of them, and carries the set-coverage check on foundation's own authored-spine commits.
scripts/install_pre_commit_hook.shInstalls the above into .git/hooks/; the install is a checklist step, and its presence is what the boot and audit layers verify.
scripts/guard-command-shape.shThe PreToolUse guard on every Bash call: tokenizes past git global flags and denies --no-verify, -n, --force and forced refspecs wherever they sit in the command, closing the flag-after-subcommand hole a prefix-matched deny cannot cover. Fail-closed, exit 2 blocks.
.claude/settings.jsonThe harness plane itself, §8 in file form: the shared safe allow-list, the deny list where deny beats allow, and the two hook wirings that make the runtime enforce the engine (PreToolUse to the shape guard, SessionStart to boot-check). Spine-protected, foundation-only edit.
probes/foundation/probe_census_parity.shThe v2.5.6 Blocker 2 guard: behaviorally drives every registered enforcer's own membership test against the shared census, both assignment and case-table forms, fail-closed on an undriveable enforcer, so the census copies can never silently diverge again.

4 Set-level authorization, the thesis in executable form

Canon anchors: §4 pending-set ledger and apply-boundary set-evaluation, §10 ratification flow. Contracts: C-SET-AUTHORIZATION.md, C-RATIFICATION-PACKET.md, COST-CAPS.md.

This is the machinery the whole architecture exists to carry: the set, not only the change, is what gets authorized, with foundation assembling and assessing and the independent human ratifying.

FileWhat it is and what runs it
PENDING-SET.mdThe visible ledger, one row per change ratified but not yet committed, shipped as the empty schema with the maintenance law and the set-evaluation receipt line verbatim from origin.
contracts/C-SET-AUTHORIZATION.mdThe governing model: the round-trip flow, the four enforced mechanisms (U4B conformance, footprint coverage §2.2, three-layer joint-edge coherence §2.3, cost brake §2.4), the member-as-manifest rule, the check-reference, the definition of done. Subordinate to the standing law by its own section L.
contracts/C-RATIFICATION-PACKET.mdThe packet schema ratify.sh assemble writes and the operator's decision taxonomy reads.
contracts/COST-CAPS.mdThe declared cost envelope the cost brake prices against, canon §1.3's ruled-not-assumed cost invariant.
scripts/pending-set.shThe ledger instrument, five verbs: list, mint (foundation-only set identity), registry, member (module writes its entry to its own outbox), and the read paths every seat uses. M1 and M2 of the mechanism.
scripts/ratify.shThe largest script in the engine (772 lines) and its heart: assemble reads the full ledger and every member entry, computes mechanical joint edges, writes the packet; assess records foundation's reasoning; ratify records the operator's single decision line. Foundation-only, resolver-gated. M3 through M5.
scripts/cost-guard.shThe cost brake: reads the usage ledger, prices rows against the caps, closed exit-code set, unreadable ledger halts.
_ratification/templates/SET-NNNN.md, _ratification/criteria/MEMBER.mdThe packet template, relocated at v2.5.7 into the templates subfolder with a header note naming the law that only allocator-minted files sit at the _ratification/ top level, and the per-member criteria schema the assembler fills.
export/EXPORT-set-authorization.mdThe methodology export: the thesis, enforcement, and first-execution method as a portable narrative, the one place the mechanism is written for reading rather than running.

Its dedicated enforcement, probed rather than asserted:

FileClaim it proves
probes/foundation/probe_set_gate.shEvery foundation commit touching an authored-spine path since the last ratified packet is covered by a ratified set member or an enumerated exemption; the post-hoc mirror of the pre-commit coverage gate.
probes/set-gate/probe_footprint_coverage_flip.shassemble refuses a set that does not cover its requirement's declared footprint; flip-proven, meaning it is seen to fail before its pass counts.
probes/set-gate/probe_semantic_hunt_flip.shThe semantic-hunt slot is unskippable: a merge decision refuses on a missing or incomplete hunt; the three-layer joint-edge gate's own guard.
scripts/test/test_set_gate_seeded_fault.shThe 59-pole seeded-fault battery over the whole area: census drift in both forms, undriveable enforcers, ledger corruption in both verbs, guard bypass shapes with benign controls, the SLOTS bypass, the shipped-layout genesis mint proven at exit 0 with an idempotent re-mint, the planted top-level template seen to fail, and positive controls. The engine's own acceptance evidence, run at every seal.

5 The work lifecycle, dispatch to audited closure

Canon anchors: §3 discipline rules, §4 receipts ledger. Schemas: the schema/ directory whole.

FileRole
schema/state-machine.mdThe work-package lifecycle with the no-fake-closures property as graph structure: there is no IN_PROGRESS to CLOSED edge; only an auditor-reproduced receipt closes.
schema/work-package.md, schema/receipt.mdThe typed shapes of the unit of work and the proof it ran.
schema/verification.mdVerification and audit rules: Ring 0, WAIVED, spot-audit, bounded rework.
schema/concurrency.mdThe concurrency rules under which lanes and workers overlap.
dispatch/LATEST.mdThe live orchestrator pointer, spine-protected, so status is read from a file rather than a screenshot; ships as the skeleton.
scripts/spawn_build_worker.shThe build-worker spawner: a backgrounded worker via claude -p, one bounded work package per spawn.
scripts/receipt-ledger.pyThe receipt single-allocator and uniqueness verifier: fixes the same-second collision class in receipt ids; applied by foundation at reap, by workers at emit, and by the auditor at verify.
scripts/validate_sprint_doc.pyThe sprint-doc section validator the dispatch track closes against.
contracts/ref-impl/emit_receipt_ref.sh, apply_ref.sh, fire_ref.sh, refusal_test.shThe runnable neutral reference implementations: how a receipt is emitted, how an apply wraps, how a gate fires, and the refusal test proving mediation actually refuses. The adopter's copy-from surface for their own C-DB and C-GATE fills.
contracts/C-DB.md, contracts/C-GATE.mdThe mediated side-effect slots: the database as a governed contract surface with the mediated-write-zero invariant, and the metered-execution gate slot. Shipped as slots; the adopter's substrate fills them.
contracts/OPERATING-DISCIPLINE.mdHow work proceeds day to day, the contract form of canon §3.
disciplines.mdThe standing disciplines and pattern library: PASS-0 premise verification, prior-art-first, halt-loud, cited by the boot creed's trigger-to-cite convention.

6 Merge, reap, and lane currency

Canon anchor: §7.2 retirement as the mirror event. Contract: SPEC-REAPER.md.

FileWhat it is and what runs it
scripts/reap_at_merge.shAudit-at-merge, the merge-time backstop: substrate guard reading the shared census, the forced-merge-path sentinel, receipt canonicalization via receipt-ledger.py, the five-state prefix-match. Run by foundation at every module or executor merge.
scripts/reaper.shThe worktree-lifecycle garbage collector implementing SPEC-REAPER: reap-at-merge cleanup, stale-lock reaping, the force-remove guard. Fully lane-agnostic.
scripts/lane_currency_gate.shThe spine-to-module mirror of reap: brings a module lane content-fresh with the trunk without letting it touch the spine.
contracts/SPEC-REAPER.mdThe lifecycle contract the two scripts implement.

7 Communication, relay, and escalation

Canon anchor: §5 communication architecture: transport lives outside every participant. Contract: SPEC-DOORBELL.md. Protocol: _knowledge/COORDINATION.md.

FileWhat it is and what runs it
scripts/inbox.shThe lane-resolved spine-inbox reader, the hub-and-spoke relay engine over _orchestration/relay-inbox/<seat>/. Every lane's first action each turn.
scripts/doorbell.shThe SPEC-DOORBELL wrapper: tmux is the bell, the git inbox is the transport, payload never rides the bell, a dropped bell delays and never loses. Rung by foundation at dispatch.
scripts/signal.shThe durable operator-to-integrator signal, born from a dropped GO typed into a mid-turn pane: directives become files.
scripts/status.shObservable state without attaching to a pane, the §7 observability property as a command.
contracts/SPEC-DOORBELL.mdThe contract: an actionable payload committed but unrung is an incomplete output; the ring completes it.
_knowledge/COORDINATION.mdThe full coordination protocol: hub-and-spoke, inbox and outbox, the integrator clauses, the module-to-foundation asymmetry invariant.
_escalations/escalation-003.mdThe shipped worked example of a STOP-AND-SURFACE riding the escalation path, so an adopter's first conflict has a filed precedent to imitate.

8 Standing audit and enforcement

Canon anchor: §4 enforcement mechanisms: invariants are probed, not asserted, the component most governance frameworks lack.

FileWhat it is and what runs it
agents/post-commit-hook.shThe D1 lane-aware reap-then-audit hook, canonical source for .git/hooks/post-commit: module marker and push, foundation reap plus push plus doorbell auto-fire, then the backgrounded auditor. Fires after every spine commit.
scripts/install_post_commit_hook.shIts installer.
agents/auditor-contract.md, agents/audit-system-prompt.mdThe independent auditor: its contract (files, never fixes) and the system prompt the hook launches it with.
agents/standing-probes.yamlThe declared registry of nine standing probes with run_by and schedule: mediated-write-zero, orchestration-freshness, auditor-liveness, set-gate, state-propagation, the two set-gate flip probes, census-parity, discrimination-proof-neutral. An invariant's health is its streak here, not its prose.
probes/discrimination_proof_neutral.shProves the probe harness itself distinguishes pass from fail with zero adopter infrastructure, so a green board is never vacuous.
probes/foundation/probe_auditor_liveness.pyFail-never-warn liveness of the post-commit trigger itself: detection machinery checked from outside the participant.
probes/foundation/probe_state_propagation.shA foundation commit touching authored-spine paths must refresh the anti-stale HEAD pin, or a cold boot re-grounds stale.
issues_register.mdThe single append-aware defect and named-wait record, first-class per canon §4, seeded empty.
scripts/audit_issue_register.pyThe register's discipline tool: push-drift flagging for the best-effort push-at-close, plus register-shape enforcement.
scripts/governance.shCite-before-raise: no settled decision is re-raised without citing the record, the §10 no-re-gating rule as a command.
scripts/check_orchestration_freshness.shThe orchestration-freshness probe body over the local session-state surface and the decision log.

9 Instantiation, adoption, and upgrade

Canon anchors: §11 packaging and adoption, §12 instantiation checklist.

FileRole
ADOPTION-COVER.mdThe read-first cover: what this is, what order to read in, both version axes on line 2.
GETTING-STARTED-LINUX-MAC.mdThe adopter's walk from unzip to first launched seat on the supported floor.
CHECKLIST.mdThe instantiation checklist in executable order, the §12 list as a working document.
OPERATOR-GUIDE.mdThe operator-side companion: what the human at the apex does and answers.
OPERATOR-CHAT-SETUP.mdThe chat-side setup page: project, bootstrap, and why a session wakes up lost without them.
SLOTS.mdThe single inventory of every adopter slot, one row each, and the authority the upgrade classifier reads to tell a slot fill from an engine delta.
docs/FOUNDATION.mdThe project rationale and invariants skeleton, shipped with authoring instructions for the adopting project's chat architect to fill.
docs/CHAT-SEAT-PROJECT-INSTRUCTIONS_skeleton.mdThe chat-seat charter skeleton, the §1.1 chat-seat law instantiated per project.
docs/FIELD-EVIDENCE_skeleton.mdThe conformed field-evidence log schema, canon §4, seeded per project.
docs/BOOT-CHECK-PROPAGATION.mdHow the one boot-check script propagates to every lane's bootstrap by call, never by copy.
docs/ENGINE-UPDATE.mdThe upgrade procedure: how an adopter takes a new engine version over their filled slots.
scripts/engine-update-classify.shThe mechanical half of that upgrade: classifies every changed path as slot fill to preserve or engine delta to apply, with no model inside the classifier; judgment goes only to per-conflict rulings.
scripts/test/test_engine_update_classify.shIts seeded-fault battery.
scripts/test/test_resolve_lane_seeded_fault.shThe identity resolver's seeded-fault battery, proving the halt paths halt.
scripts/sync_knowledge.shThe tiered publish of decision-load-bearing surfaces for chat-seat project ingestion, the code end of the ferry.
scripts/install_skills.shInstalls the in-repo skill home to the runtime's skill directory; ships the single generic code-build skill, adopters extend.
scripts/rules_manifest.shThe scoped rules-manifest hash over the guard, resolver, and coordination clauses, so rule drift is detectable as a fingerprint change.

10 Release integrity and the release envelope

The release is bigger than the package: four loose files ride beside the zip, and the README is the front door to all of it. The two layers verify each other in sequence, loose first, package second, which is why they are one area.

In-zip integrity and hygiene:

FileRole
MANIFEST.sha256The per-file fingerprint manifest, 101 rows; sha256sum -c inside the unzipped package is the adopter's second verify surface.
CHANGELOG.mdThe versioned public account, additive framing in its own header, the in-place-rebuild promise on line 3.
CITATION.cffThe citation metadata, validated by its own schema validator, both axes carried.
.gitattributes, .gitignoreLine-ending and exclusion hygiene, including the local-only surfaces (settings.local.json, session state) the freshness probe expects gitignored.

The loose release layer, beside the zip:

FileRole
README.mdThe front door and the map of the whole release. Every section of it is backed by something executable or fingerprinted, which is what separates it from marketing: the thesis restated in the additive form; the two-artifact two-license split; the release contents list; the substrate floor; the quick start; the two-axis verify rule; the license summary. Its section-by-section wiring is below.
LICENSE.mdThe licensing envelope: the engine under Apache 2.0 with the Commons Clause, the canon/ directory carved out under CC BY 4.0, the required notice. The carve-out line ("everything in this package except the canon/ directory") is a claim about the zip's own layout, and the layout honors it.
GOVERNED_MULTI_AGENT_ARCHITECTURE_v1_6_1.pdfThe canon in reading form, the same version the zip carries as canon/..._PUBLIC.md. Two renderings, one version; the in-zip markdown is the fingerprint-pinned copy the manifest and the citation law bind to.
SHA256SUMSThe first verify surface: four rows, the zip and the three documents above, checked before anything is unzipped. The zip's filename in row 1 is load-bearing, since sha256sum -c matches by name.

The README's sections, each mapped to what makes it true:

README sectionBacked by
The correctionThe additive-framing law verbatim: set-level authorization on top of per-change review, never instead of it. The same sentence the CHANGELOG header and every public surface carry; area 4 is its implementation.
Two artifacts, two licensesLICENSE.md beside it and the canon's own CC BY line; the carve-out matches the zip layout.
What is in this releaseThe four loose files plus the zip, enumerated. The license text travels beside the zip and on the release page; verify the full set together.
Prerequisites, the substrate floorscripts/preflight.sh is this section as a command: it checks exactly the floor stated here, reports, halts, and provisions nothing, per the floor ruling.
Quick startStep 1 is SHA256SUMS; step 2 is MANIFEST.sha256; step 3 sets execute bits; step 4 is launch-orc.sh, area 2.
VerifyThe two-axis citation law as procedure: package version and canon pin, both surfaces in order, fingerprints published at versions.html.
License summaryThe one-paragraph restatement of LICENSE.md; the file governs, the summary points.

The README carries no engine version label by design: it points at versions.html for the current version and fingerprints, so the file stays stable across releases while the fingerprints move where they are published.


Execution wiring, the whole engine as a timeline

At adoption: preflight.sh clears the floor → CHECKLIST.md walks §12 → hooks installed (install_pre_commit_hook.sh, install_post_commit_hook.sh) → slots filled per SLOTS.md (including creating seats.yaml) → docs/FOUNDATION.md authored.

At seat launch: operator runs orc-up.sh <lane> → launch-orc.sh resolves the stamp, refuses double-launch, creates {project}-{lane} → claude --agent orc loads orc.md → SessionStart hook fires boot-check.sh → the session derives identity via resolve-lane.sh, reads its charter, reads dispatch/LATEST.md, checks its inbox.

Per tool call: the PreToolUse hook runs guard-command-shape.sh on every Bash invocation.

Per change: foundation dispatches into an inbox and rings doorbell.sh → the lane works on its branch → worker emits artifact plus receipt (receipt-ledger.py allocates) → probe runs → the post-commit hook's auditor reproduces → only then does the state machine allow CLOSED.

Per commit: .git/hooks/pre-commit (from agents/pre-commit-hook.sh) reads spine-census.sh plus declared-spine-paths.sh at HEAD and blocks non-writer spine writes and uncovered foundation writes; .git/hooks/post-commit reaps, pushes, and launches the auditor.

Per set: members enter PENDING-SET.md via pending-set.sh → ratify.sh assemble computes joint edges and writes the packet → assess records foundation's reasoning, cost-guard.sh prices it → the operator writes one decision line → ratify.sh ratify records it → foundation merges, reap_at_merge.sh backstops, pushes at close.

Continuously: the nine probes in standing-probes.yaml run on their schedules, ledgered; audit_issue_register.py flags push drift; the seeded-fault batteries re-prove the gates can fail at every release.

Coverage account

The release is 106 files: 102 in the sealed package plus 4 loose beside the zip. In-package assignment: area 1 carries 1; area 2 carries 17 (10 identity files plus the 7 agent definitions); area 3 carries 7; area 4 carries 12; area 5 carries 14; area 6 carries 4; area 7 carries 7; area 8 carries 12; area 9 carries 17; area 10's in-zip table carries 4. Total 95, plus the 7 remaining: PENDING-SET.md counted in area 4, CLAUDE.md and disciplines.md counted in areas 2 and 5, dispatch/LATEST.md in area 5, issues_register.md in area 8, _escalations/escalation-003.md in area 7, export/EXPORT-set-authorization.md in area 4. The 4 loose files (README.md, LICENSE.md, the canon PDF, SHA256SUMS) carry their own rows in area 10's loose-layer table. Every file in the release appears exactly once above; none is unassigned.

One absence is load-bearing and named: seats.yaml does not ship. It is created at instantiation, and the engine's enforcement reads it at HEAD from the moment it exists.

This map is re-derived from the tree at every engine version; nothing in it is maintained by hand against drift. GMAA · gmaa.ai · cite by version.