[
  {
    "id": "nist-ai-rmf-public-framework-candidate",
    "title": "NIST AI Risk Management Framework",
    "source_owner": "National Institute of Standards and Technology",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "public_standards_or_regulatory",
    "proposed_url": "https://www.nist.gov/itl/ai-risk-management-framework",
    "allowed_origin": "https://www.nist.gov",
    "allowed_path_prefix": "/itl/ai-risk-management-framework",
    "allowed_use": ["AI governance comparison", "risk-management framing", "trustworthy AI public context"],
    "claim_boundary": "current_public_context_only_not_package_authority; authoritative only for NIST public material",
    "citation_boundary": "cite as current/public context separate from package citations",
    "citation_label": "NIST AI RMF current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "existing_enabled_production_baseline_only",
    "enablement_recommendation": "Remain the only enabled current/public production source until a later owner-approved issue changes the catalog.",
    "reason_for_inclusion": "Existing NIST AI RMF current/public production baseline and official public AI risk management framework material.",
    "limitations": ["Not package authority", "Not company policy", "Not approval for any tool, vendor, model, data class, workflow, or production use"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Catalog baseline entry. The repo-side registry entry remains candidate-only and is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "nist-ssdf-sp-800-218-candidate",
    "title": "NIST Secure Software Development Framework SP 800-218 final v1.1",
    "source_owner": "NIST Computer Security Resource Center",
    "source_class": "security_ai_safety_framework_source",
    "source_type": "secure_software_development_framework",
    "proposed_url": "https://csrc.nist.gov/pubs/sp/800/218/final",
    "allowed_origin": "https://csrc.nist.gov",
    "allowed_path_prefix": "/pubs/sp/800/218/final",
    "allowed_use": ["secure software development comparison", "software supply-chain screening", "control expectation comparison"],
    "claim_boundary": "current_public_secure_software_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public security guidance separate from package citations",
    "citation_label": "NIST SSDF current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "First source in the staged governance/security batch only after separate owner approval, preview smoke, and production smoke.",
    "reason_for_inclusion": "Official NIST secure software development framework material for SP 800-218 final version 1.1 with an existing reviewed public URL.",
    "limitations": ["Voluntary guidance can be mistaken for enterprise approval", "HTML extraction may lose tables or caveats", "NIST SP 800-218 Rev. 1 Initial Public Draft is excluded from production enablement"],
    "verification_status": "sp_800_218_final_v1_1_verified_2026-06-25",
    "readiness_metadata": {
      "canonical_url": "https://csrc.nist.gov/pubs/sp/800/218/final",
      "fetch_url": "https://csrc.nist.gov/pubs/sp/800/218/final",
      "content_type": "text/html; charset=utf-8",
      "version_or_date": "SP 800-218 final, version 1.1, February 2022",
      "publication_current_final_draft_status": "final v1.1 current target; Rev. 1 Initial Public Draft excluded from production scope",
      "public_fetchable_status": "HTTP 200 public HTML, zero redirects, no login observed on 2026-06-25",
      "license_public_use_notes": "Official NIST public publication page. Use only as current/public context and cite the NIST page.",
      "robots_rate_limit_notes": "CSRC robots probe redirected to CSRC home HTML in this environment. Use exact path only, no broad CSRC crawling, low-rate retrieval only.",
      "verifier": "Codex official-source probe",
      "verification_timestamp": "2026-06-25T13:32:28Z",
      "retrieval_readiness_status": "candidate_ready_for_owner_review_not_enabled",
      "production_enablement_status": "not_enabled",
      "package_authority_status": "not_package_authority",
      "explicit_exclusions": ["NIST SP 800-218 Rev. 1 Initial Public Draft", "broad CSRC crawling", "unrelated SP 800-218 drafts", "PDF extraction until separately citation-tested"],
      "depends_on_owner_authorization": true,
      "depends_on_later_cloudflare_runtime_config_change": true,
      "planned_future_enablement_sequence": "stage_1_ssdf_first_after_explicit_owner_authorization"
    },
    "notes": "Candidate-only source. SP 800-218 final v1.1 is the only planned SSDF stage-1 target; SP 800-218 Rev. 1 Initial Public Draft remains excluded or candidate-only. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "nist-ai-rmf-playbook-candidate",
    "title": "NIST AI RMF Playbook",
    "source_owner": "NIST AI Resource Center",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "public_standards_or_regulatory",
    "proposed_url": "https://airc.nist.gov/airmf-resources/playbook/",
    "allowed_origin": "https://airc.nist.gov",
    "allowed_path_prefix": "/airmf-resources/playbook/",
    "allowed_use": ["same-family AI RMF enrichment", "AI governance comparison after package support exists"],
    "claim_boundary": "current_public_context_only_not_package_authority; authoritative only for NIST AIRC public material",
    "citation_boundary": "cite as current/public NIST companion context separate from package citations",
    "citation_label": "NIST AI RMF Playbook current/public context",
    "freshness_review_cadence": "living_resource_review_before_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Same-family candidate after freshness review.",
    "reason_for_inclusion": "Official NIST AI RMF companion material with an existing reviewed public URL.",
    "limitations": ["Living resource requires freshness review", "Not a replacement for the enabled NIST AI RMF source"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "owasp-genai-llm-top-10-2025-candidate",
    "title": "OWASP GenAI Security Project 2025 GenAI Top 10",
    "source_owner": "OWASP Foundation GenAI Security Project",
    "source_class": "security_ai_safety_framework_source",
    "source_type": "llm_application_security_framework",
    "proposed_url": "https://genai.owasp.org/llm-top-10/",
    "allowed_origin": "https://genai.owasp.org",
    "allowed_path_prefix": "/llm-top-10/",
    "allowed_use": ["LLM application security comparison", "prompt injection and disclosure risk framing", "implementation screening after package support exists"],
    "claim_boundary": "current_public_security_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public LLM security framework context separate from package citations",
    "citation_label": "OWASP 2025 GenAI Top 10 current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Second source in the staged governance/security batch only after NIST SSDF final v1.1 passes preview and production smoke.",
    "reason_for_inclusion": "Respected public GenAI application security framework with an existing reviewed public URL bound to the 2025 GenAI Top 10.",
    "limitations": ["Community-maintained framework", "Not company policy", "Not a complete control set", "Historical or unversioned LLM Top 10 naming is excluded from this planned enablement"],
    "verification_status": "official_2025_genai_top_10_verified_2026-06-25",
    "readiness_metadata": {
      "canonical_url": "https://genai.owasp.org/llm-top-10/",
      "fetch_url": "https://genai.owasp.org/llm-top-10/",
      "content_type": "text/html; charset=UTF-8",
      "version_or_date": "2025 Top 10 page; HTTP Last-Modified header observed 2026-06-23",
      "publication_current_final_draft_status": "2025_genai_top_10_target; historical or unversioned LLM Top 10 naming excluded",
      "public_fetchable_status": "HTTP 200 public HTML, zero redirects, no login observed on 2026-06-25",
      "license_public_use_notes": "Public OWASP GenAI Security Project material. Use only as current/public security framework context, not company policy or package authority.",
      "robots_rate_limit_notes": "robots.txt allows User-agent all and publishes sitemaps. Use exact path only, no broad genai.owasp.org or OWASP crawling.",
      "verifier": "Codex official-source probe",
      "verification_timestamp": "2026-06-25T13:32:28Z",
      "runtime_retrieval_profile": {
        "profile_id": "owasp_genai_2025_bounded_html_extract_v01",
        "activation_status": "inactive_repair_only",
        "max_response_bytes": 1048576,
        "max_snippet_chars": 4000,
        "required_text_markers": ["LLM01:2025", "LLM02:2025", "LLM03:2025", "LLM04:2025", "LLM05:2025", "LLM06:2025", "LLM07:2025", "LLM08:2025", "LLM09:2025", "LLM10:2025"],
        "sizing_rule": "Only the exact OWASP 2025 GenAI Top 10 source ID, origin, and path may use this larger bounded HTML extraction cap. The global default remains 120000 bytes.",
        "boundary_notes": "This profile repairs sizing readiness only. It does not enable retrieval, broaden OWASP crawling, authorize sibling pages, or promote OWASP to package authority."
      },
      "retrieval_readiness_status": "candidate_ready_for_owner_review_not_enabled",
      "production_enablement_status": "not_enabled",
      "package_authority_status": "not_package_authority",
      "explicit_exclusions": ["OWASP Top 10 for LLMs 2023/24", "ambiguous LLM Top 10 naming", "broad OWASP project crawling", "sibling pages unless separately verified"],
      "depends_on_owner_authorization": true,
      "depends_on_later_cloudflare_runtime_config_change": true,
      "planned_future_enablement_sequence": "stage_2_owasp_after_ssdf_preview_and_production_smoke"
    },
    "notes": "Candidate-only source. This row binds to the 2025 OWASP GenAI Security Project / GenAI Top 10 and not an ambiguous historical or unversioned LLM Top 10. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "mitre-atlas-candidate-deferred",
    "title": "MITRE ATLAS",
    "source_owner": "MITRE",
    "source_class": "security_ai_safety_framework_source",
    "source_type": "ai_threat_modeling_framework",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["AI threat-modeling comparison after package support exists"],
    "claim_boundary": "current_public_security_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public AI threat-modeling context only after exact path verification",
    "citation_label": "MITRE ATLAS current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_path_verification_required",
    "enablement_recommendation": "Defer until a narrow public path is verified in a later issue.",
    "reason_for_inclusion": "AI-specific adversarial threat-modeling source named in the source-class model.",
    "limitations": ["Prior root URL review left path scope too broad", "Not package authority", "Not tool or vendor approval"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "cisa-secure-by-design-candidate",
    "title": "CISA Secure by Design",
    "source_owner": "Cybersecurity and Infrastructure Security Agency",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "government_cybersecurity_guidance",
    "proposed_url": "https://www.cisa.gov/securebydesign",
    "allowed_origin": "https://www.cisa.gov",
    "allowed_path_prefix": "/securebydesign",
    "allowed_use": ["secure-by-design comparison", "secure engineering posture comparison"],
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public government cybersecurity context separate from package citations",
    "citation_label": "CISA Secure by Design current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Candidate after NIST and OWASP review sequencing.",
    "reason_for_inclusion": "Official CISA public cybersecurity guidance with an existing reviewed public URL.",
    "limitations": ["Not enterprise policy", "Not Cloudflare, provider, model, workflow, or production approval"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "cisa-ai-guidance-candidate",
    "title": "CISA Artificial Intelligence",
    "source_owner": "Cybersecurity and Infrastructure Security Agency",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "government_cybersecurity_guidance",
    "proposed_url": "https://www.cisa.gov/ai",
    "allowed_origin": "https://www.cisa.gov",
    "allowed_path_prefix": "/ai",
    "allowed_use": ["AI cybersecurity public context", "AI risk posture comparison"],
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public government AI cybersecurity context separate from package citations",
    "citation_label": "CISA AI current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Candidate only after exact claim review.",
    "reason_for_inclusion": "Official CISA public AI page with an existing reviewed public URL.",
    "limitations": ["Landing page may aggregate announcements", "Not policy approval or package authority"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "cisa-nsa-ncsc-secure-ai-system-development-guidelines-candidate",
    "title": "NCSC/CISA/NSA Guidelines for Secure AI System Development v1.0",
    "source_owner": "UK National Cyber Security Centre with CISA, NSA, and international partners",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "government_cybersecurity_guidance",
    "proposed_url": "https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development",
    "allowed_origin": "https://www.ncsc.gov.uk",
    "allowed_path_prefix": "/collection/guidelines-secure-ai-system-development",
    "allowed_use": ["secure AI system development comparison", "secure AI lifecycle guidance comparison", "government cybersecurity current context after package support exists"],
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public joint secure AI guidance separate from package citations and only within exact collection scope",
    "citation_label": "NCSC/CISA/NSA secure AI guidance current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Third source in the staged governance/security batch only after OWASP GenAI 2025 Top 10 passes preview and production smoke.",
    "reason_for_inclusion": "Official NCSC-hosted secure AI system development guidance naming CISA, NSA, and international partners, scoped to an exact public collection path.",
    "limitations": ["No broad CISA, NSA, NCSC, or partner-domain crawl", "PDF runtime retrieval requires separate extraction and citation testing", "Not company policy", "Not package authority"],
    "verification_status": "exact_ncsc_collection_path_verified_2026-06-25",
    "readiness_metadata": {
      "canonical_url": "https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development",
      "fetch_url": "https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development",
      "content_type": "text/html; charset=UTF-8",
      "version_or_date": "Version 1.0, published 2023-11-27, reviewed 2023-11-27",
      "publication_current_final_draft_status": "published_version_1_0_exact_collection_target",
      "public_fetchable_status": "HTTP 200 public HTML, zero redirects, no login observed on 2026-06-25; official PDF also returned HTTP 200 application/pdf but is extraction-pending",
      "license_public_use_notes": "Public NCSC-hosted secure AI guidance naming CISA, NSA, and international partners. Use only as current/public government cybersecurity context.",
      "robots_rate_limit_notes": "NCSC robots.txt content signals show search=yes and ai-train=no. Use exact collection path only, no broad government-domain crawling.",
      "verifier": "Codex official-source probe",
      "verification_timestamp": "2026-06-25T13:32:28Z",
      "retrieval_readiness_status": "candidate_ready_for_owner_review_not_enabled_html_only",
      "production_enablement_status": "not_enabled",
      "package_authority_status": "not_package_authority",
      "explicit_exclusions": ["broad cisa.gov crawling", "broad nsa.gov crawling", "broad ncsc.gov.uk crawling", "partner-domain crawling", "sibling NCSC pages outside exact collection path", "PDF runtime retrieval until extraction and citation testing pass"],
      "depends_on_owner_authorization": true,
      "depends_on_later_cloudflare_runtime_config_change": true,
      "planned_future_enablement_sequence": "stage_3_cisa_nsa_ncsc_after_owasp_preview_and_production_smoke"
    },
    "notes": "Candidate-only source. The exact NCSC collection path is the planned scope for the joint CISA / NSA / NCSC secure AI guidance; broad government-domain crawling and sibling pages are excluded. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "uk-ncsc-ai-security-guidance-candidate-deferred",
    "title": "UK NCSC AI/security guidance",
    "source_owner": "UK National Cyber Security Centre",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "government_cybersecurity_guidance",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["AI and security public guidance comparison after package support exists"],
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public government cybersecurity context only after exact URL verification",
    "citation_label": "UK NCSC AI/security current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later verification issue.",
    "reason_for_inclusion": "Official cybersecurity source named in the expanded source-class model.",
    "limitations": ["Broad placeholder remains deferred because exact joint secure AI guidance is recorded separately", "Not package authority", "Not company policy"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred candidate-only source. Broad UK NCSC AI/security guidance remains deferred; the exact joint secure AI guidance collection is recorded separately. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "enisa-ai-cybersecurity-guidance-candidate-deferred",
    "title": "ENISA AI/cybersecurity guidance",
    "source_owner": "European Union Agency for Cybersecurity",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "government_cybersecurity_guidance",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["EU cybersecurity and AI risk context after package support exists"],
    "claim_boundary": "current_public_cybersecurity_guidance_only_not_package_authority",
    "citation_boundary": "cite as current/public agency guidance only after exact URL verification",
    "citation_label": "ENISA AI/cybersecurity current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later verification issue.",
    "reason_for_inclusion": "Official cybersecurity agency named in the expanded source-class model.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Not package authority", "Not company policy"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "eu-ai-act-official-pages-candidate-deferred",
    "title": "EU AI Act official pages",
    "source_owner": "European Union official publication owner to be verified",
    "source_class": "government_standards_regulator_adjacent_authority",
    "source_type": "public_standards_or_regulatory",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["official regulatory public context after package support exists"],
    "claim_boundary": "current_public_regulatory_context_only_not_package_authority_not_legal_advice",
    "citation_boundary": "cite as current/public official regulatory context only after exact URL and licensing verification",
    "citation_label": "EU AI Act official current/public context",
    "freshness_review_cadence": "verify_exact_public_path_and_citation_posture_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later legal-source verification issue.",
    "reason_for_inclusion": "Official regulatory source class named in the expanded catalog.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Not legal advice", "Not company policy", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "microsoft-learn-azure-ai-docs-candidate-deferred",
    "title": "Microsoft Learn Azure AI docs",
    "source_owner": "Microsoft Learn",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Azure AI platform-specific facts", "documented feature and configuration reference"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as Microsoft vendor documentation only for Microsoft platform facts",
    "citation_label": "Microsoft Azure AI docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_feature_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later vendor-doc verification issue.",
    "reason_for_inclusion": "Official vendor documentation class needed for platform-specific facts beyond NIST.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor documentation is not neutral governance authority", "Exclude marketing pages"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred vendor candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "microsoft-copilot-studio-docs-candidate-deferred",
    "title": "Microsoft Copilot Studio docs",
    "source_owner": "Microsoft Learn",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Copilot Studio platform-specific facts", "documented feature and configuration reference"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as Microsoft vendor documentation only for Microsoft platform facts",
    "citation_label": "Microsoft Copilot Studio docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_feature_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later vendor-doc verification issue.",
    "reason_for_inclusion": "Official vendor documentation class needed for platform-specific Copilot Studio facts.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor documentation is not neutral governance authority", "Exclude marketing pages"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred vendor candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "aws-bedrock-docs-candidate-deferred",
    "title": "AWS Bedrock docs",
    "source_owner": "AWS documentation",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Bedrock platform-specific facts", "documented feature and configuration reference"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as AWS vendor documentation only for AWS platform facts",
    "citation_label": "AWS Bedrock docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_feature_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later vendor-doc verification issue.",
    "reason_for_inclusion": "Official vendor documentation class needed for platform-specific AWS Bedrock facts.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor documentation is not neutral governance authority", "Exclude marketing pages"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred vendor candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "aws-well-architected-framework-candidate-deferred",
    "title": "AWS Well-Architected Framework",
    "source_owner": "AWS documentation",
    "source_class": "reputable_engineering_practice_source",
    "source_type": "respected_engineering_guidance",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["architecture and operational pattern comparison"],
    "claim_boundary": "vendor_published_engineering_guidance_only_not_policy_not_package_authority",
    "citation_boundary": "cite as vendor-published engineering guidance, not neutral authority",
    "citation_label": "AWS Well-Architected current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later exact path and vendor-bias review.",
    "reason_for_inclusion": "Widely used engineering practice source named in the expanded catalog.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor-published guidance is not neutral policy", "Not production approval"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred engineering candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "google-cloud-vertex-ai-docs-candidate-deferred",
    "title": "Google Cloud Vertex AI docs",
    "source_owner": "Google Cloud documentation",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Vertex AI platform-specific facts", "documented feature and configuration reference"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as Google vendor documentation only for Google platform facts",
    "citation_label": "Google Cloud Vertex AI docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_feature_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later vendor-doc verification issue.",
    "reason_for_inclusion": "Official vendor documentation class needed for platform-specific Google Cloud Vertex AI facts.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor documentation is not neutral governance authority", "Exclude marketing pages"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred vendor candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "google-sre-book-candidate",
    "title": "Google Site Reliability Engineering Book",
    "source_owner": "Google SRE",
    "source_class": "reputable_engineering_practice_source",
    "source_type": "respected_engineering_guidance",
    "proposed_url": "https://sre.google/sre-book/table-of-contents/",
    "allowed_origin": "https://sre.google",
    "allowed_path_prefix": "/sre-book/table-of-contents/",
    "allowed_use": ["reliability engineering comparison", "SLO and operations practice context"],
    "claim_boundary": "current_public_engineering_guidance_only_not_policy_not_package_authority",
    "citation_boundary": "cite as respected engineering guidance separate from package citations",
    "citation_label": "Google SRE current/public context",
    "freshness_review_cadence": "before_production_enablement_then_periodic",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Lower priority than government, standards, and security sources.",
    "reason_for_inclusion": "Mature engineering practice reference with an existing reviewed public URL.",
    "limitations": ["Vendor-published engineering material", "Not neutral standards authority", "Not production approval"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "openai-api-pricing-docs-candidate",
    "title": "OpenAI API Pricing",
    "source_owner": "OpenAI developer documentation",
    "source_class": "official_research_lab_model_provider_documentation",
    "source_type": "official_provider_documentation",
    "proposed_url": "https://developers.openai.com/api/docs/pricing",
    "allowed_origin": "https://developers.openai.com",
    "allowed_path_prefix": "/api/docs/pricing",
    "allowed_use": ["provider-specific pricing reference", "token and cost accounting context"],
    "claim_boundary": "provider_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as OpenAI provider documentation only for OpenAI-specific facts",
    "citation_label": "OpenAI pricing current/public context",
    "freshness_review_cadence": "review_before_each_pricing_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Use only for time-sensitive OpenAI-specific cost context after owner review.",
    "reason_for_inclusion": "Existing reviewed official provider documentation candidate for token and cost context.",
    "limitations": ["Time-sensitive", "Provider-specific", "Not a billing guarantee", "Not neutral governance authority"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "openai-official-docs-candidate-deferred",
    "title": "OpenAI official docs",
    "source_owner": "OpenAI",
    "source_class": "official_research_lab_model_provider_documentation",
    "source_type": "official_provider_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["OpenAI API and runtime facts", "documented capabilities and configuration reference"],
    "claim_boundary": "provider_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as OpenAI provider documentation only for OpenAI-specific facts",
    "citation_label": "OpenAI docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_model_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later provider-doc verification issue.",
    "reason_for_inclusion": "Official provider documentation class needed for provider-specific facts beyond NIST.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Provider self-claims must be caveated", "Not approval for regulated workflows"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred provider candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "openai-safety-model-system-cards-candidate-deferred",
    "title": "OpenAI safety/model/system-card pages",
    "source_owner": "OpenAI",
    "source_class": "official_research_lab_model_provider_documentation",
    "source_type": "official_provider_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["model behavior caveats", "official safety self-claims", "system-card interpretation"],
    "claim_boundary": "provider_self_claims_caveated_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as provider self-claim documentation with caveats",
    "citation_label": "OpenAI safety/model current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_model_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later provider-doc verification issue.",
    "reason_for_inclusion": "Official provider safety and model documentation class needed for model-specific caveats.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Benchmark claims need source-specific citation", "Not approval for regulated workflows"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred provider candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "anthropic-official-docs-candidate-deferred",
    "title": "Anthropic official docs",
    "source_owner": "Anthropic",
    "source_class": "official_research_lab_model_provider_documentation",
    "source_type": "official_provider_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Anthropic API and runtime facts", "documented capabilities and configuration reference"],
    "claim_boundary": "provider_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as Anthropic provider documentation only for Anthropic-specific facts",
    "citation_label": "Anthropic docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_model_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later provider-doc verification issue.",
    "reason_for_inclusion": "Official provider documentation class needed for provider-specific facts beyond NIST.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Provider self-claims must be caveated", "Not approval for regulated workflows"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred provider candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "anthropic-model-safety-pages-candidate-deferred",
    "title": "Anthropic model/safety pages",
    "source_owner": "Anthropic",
    "source_class": "official_research_lab_model_provider_documentation",
    "source_type": "official_provider_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["model behavior caveats", "official safety self-claims", "system-card interpretation"],
    "claim_boundary": "provider_self_claims_caveated_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as provider self-claim documentation with caveats",
    "citation_label": "Anthropic safety/model current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_model_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later provider-doc verification issue.",
    "reason_for_inclusion": "Official provider safety and model documentation class needed for model-specific caveats.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Benchmark claims need source-specific citation", "Not approval for regulated workflows"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred provider candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "github-actions-copilot-security-docs-candidate-deferred",
    "title": "GitHub Actions, Copilot, and security docs",
    "source_owner": "GitHub Docs",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["GitHub platform-specific facts", "Actions, Copilot, and security documentation reference"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as GitHub vendor documentation only for GitHub platform facts",
    "citation_label": "GitHub Docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_feature_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later vendor-doc verification issue.",
    "reason_for_inclusion": "Official vendor documentation class relevant to GitHub platform facts.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor documentation is not neutral governance authority", "Scope must remain platform-specific"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred vendor candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "cloudflare-workers-limits-docs-candidate",
    "title": "Cloudflare Workers Limits",
    "source_owner": "Cloudflare developer documentation",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "https://developers.cloudflare.com/workers/platform/limits/",
    "allowed_origin": "https://developers.cloudflare.com",
    "allowed_path_prefix": "/workers/platform/limits/",
    "allowed_use": ["Cloudflare Workers limit reference", "runtime platform-limit screening"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as Cloudflare vendor documentation only for Cloudflare platform facts",
    "citation_label": "Cloudflare Workers Limits current/public context",
    "freshness_review_cadence": "review_before_each_limit_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_fetchable_review_required",
    "enablement_recommendation": "Use only for Cloudflare-specific limit questions after owner review.",
    "reason_for_inclusion": "Existing reviewed official vendor documentation candidate for platform-limit context.",
    "limitations": ["Plan and limits may change", "Not deployment approval", "Not neutral governance authority"],
    "verification_status": "existing_registry_verified_2026-06-24",
    "notes": "Candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "cloudflare-pages-workers-access-docs-candidate-deferred",
    "title": "Cloudflare Pages, Workers, and Access docs",
    "source_owner": "Cloudflare developer documentation",
    "source_class": "official_vendor_documentation",
    "source_type": "official_vendor_documentation",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Cloudflare deployment platform-specific facts", "Pages, Workers, and Access documentation reference"],
    "claim_boundary": "vendor_specific_current_public_reference_only_not_neutral_governance_authority_not_package_authority",
    "citation_boundary": "cite as Cloudflare vendor documentation only for Cloudflare platform facts",
    "citation_label": "Cloudflare docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_enablement_and_before_feature_sensitive_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later exact path review.",
    "reason_for_inclusion": "Official vendor documentation class relevant to this deployment platform.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Access and WAF configuration remains external", "Not production approval"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred vendor candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "microsoft-architecture-center-candidate-deferred",
    "title": "Microsoft Architecture Center",
    "source_owner": "Microsoft Learn",
    "source_class": "reputable_engineering_practice_source",
    "source_type": "respected_engineering_guidance",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["architecture pattern comparison", "engineering practice context"],
    "claim_boundary": "vendor_published_engineering_guidance_only_not_policy_not_package_authority",
    "citation_boundary": "cite as vendor-published engineering guidance, not neutral authority",
    "citation_label": "Microsoft Architecture Center current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer to later exact path and vendor-bias review.",
    "reason_for_inclusion": "Vendor-published engineering practice source named in the expanded catalog.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Vendor-published guidance is not neutral policy", "Not production approval"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred engineering candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "cncf-kubernetes-official-docs-candidate-deferred",
    "title": "CNCF/Kubernetes official docs",
    "source_owner": "CNCF/Kubernetes documentation owners",
    "source_class": "reputable_engineering_practice_source",
    "source_type": "respected_engineering_guidance",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["orchestration and platform operation pattern comparison"],
    "claim_boundary": "current_public_engineering_guidance_only_not_policy_not_package_authority",
    "citation_boundary": "cite as official engineering documentation separate from package citations",
    "citation_label": "CNCF/Kubernetes docs current/public context",
    "freshness_review_cadence": "verify_exact_public_path_before_production_enablement",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer unless directly relevant to a later package-supported question.",
    "reason_for_inclusion": "Official engineering documentation class named in the expanded catalog.",
    "limitations": ["Exact URL not verified in existing repo artifacts", "Include only if directly relevant", "Not production approval"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred engineering candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "thoughtworks-technology-radar-signal-deferred",
    "title": "Thoughtworks Technology Radar",
    "source_owner": "Thoughtworks",
    "source_class": "reputable_engineering_practice_source",
    "source_type": "opinion_signal_source",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["opinion and trend signal only"],
    "claim_boundary": "opinion_signal_only_not_authority_not_package_authority",
    "citation_boundary": "cite as opinion/signal only if a later issue approves its use",
    "citation_label": "Thoughtworks Radar signal context",
    "freshness_review_cadence": "verify_exact_public_path_and_signal_only_scope_before_any_use",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "opinion_signal_only_deferred",
    "enablement_recommendation": "Do not enable as authoritative source.",
    "reason_for_inclusion": "Opinion/signal example named in the expanded catalog.",
    "limitations": ["Opinion signal only", "Not authority", "Not final evidence", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Deferred signal-only candidate. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "reddit-community-source-excluded",
    "title": "Reddit forums",
    "source_owner": "Reddit community contributors",
    "source_class": "community_practitioner_source",
    "source_type": "community_signal_source",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["weak signal only if a later owner-approved issue defines a narrow reason"],
    "claim_boundary": "weak_signal_only_not_authority_not_final_evidence_not_package_authority",
    "citation_boundary": "cite as anecdotal weak signal only if later approved",
    "citation_label": "Reddit weak-signal context",
    "freshness_review_cadence": "excluded_by_default",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "excluded_by_default",
    "enablement_recommendation": "Do not enable for runtime current/public source retrieval.",
    "reason_for_inclusion": "Community-source boundary example required by the expanded catalog.",
    "limitations": ["Anecdotal", "Not authority", "Not final evidence", "Requires independent authoritative confirmation elsewhere"],
    "verification_status": "excluded_by_default_not_fetchable",
    "notes": "Excluded community candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "hacker-news-community-source-excluded",
    "title": "Hacker News",
    "source_owner": "Hacker News community contributors",
    "source_class": "community_practitioner_source",
    "source_type": "community_signal_source",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["weak signal only if a later owner-approved issue defines a narrow reason"],
    "claim_boundary": "weak_signal_only_not_authority_not_final_evidence_not_package_authority",
    "citation_boundary": "cite as anecdotal weak signal only if later approved",
    "citation_label": "Hacker News weak-signal context",
    "freshness_review_cadence": "excluded_by_default",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "excluded_by_default",
    "enablement_recommendation": "Do not enable for runtime current/public source retrieval.",
    "reason_for_inclusion": "Community-source boundary example required by the expanded catalog.",
    "limitations": ["Anecdotal", "Not authority", "Not final evidence", "Requires independent authoritative confirmation elsewhere"],
    "verification_status": "excluded_by_default_not_fetchable",
    "notes": "Excluded community candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "stack-overflow-community-source-excluded",
    "title": "Stack Overflow",
    "source_owner": "Stack Overflow contributors",
    "source_class": "community_practitioner_source",
    "source_type": "community_signal_source",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["weak signal only if a later owner-approved issue defines a narrow reason"],
    "claim_boundary": "weak_signal_only_not_authority_not_final_evidence_not_package_authority",
    "citation_boundary": "cite as anecdotal weak signal only if later approved",
    "citation_label": "Stack Overflow weak-signal context",
    "freshness_review_cadence": "excluded_by_default",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "excluded_by_default",
    "enablement_recommendation": "Do not enable for runtime current/public source retrieval.",
    "reason_for_inclusion": "Community-source boundary example required by the expanded catalog.",
    "limitations": ["Anecdotal", "Not authority", "Not final evidence", "Requires independent authoritative confirmation elsewhere"],
    "verification_status": "excluded_by_default_not_fetchable",
    "notes": "Excluded community candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "github-issues-discussions-community-source-deferred",
    "title": "GitHub issues and discussions",
    "source_owner": "Project-specific repository owners and community contributors",
    "source_class": "community_practitioner_source",
    "source_type": "community_signal_source",
    "proposed_url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["weak signal only", "project-specific issue evidence only after separate owner review"],
    "claim_boundary": "weak_signal_only_not_authority_not_final_evidence_not_package_authority",
    "citation_boundary": "cite as weak signal or project-specific issue evidence only if later approved",
    "citation_label": "GitHub issue/discussion weak-signal context",
    "freshness_review_cadence": "deferred_by_default",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "package_governance_owner_review_required",
    "initial_posture": "community_source_deferred_by_default",
    "enablement_recommendation": "Do not enable without project-specific owner review and narrow source purpose.",
    "reason_for_inclusion": "Community and issue-tracker boundary example required by the expanded catalog.",
    "limitations": ["Anecdotal unless official project maintainers confirm", "Not vendor fact source by default", "Not final evidence"],
    "verification_status": "deferred_by_default_not_fetchable",
    "notes": "Deferred community candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "fda-21-cfr-part-11-candidate",
    "title": "FDA / CFR Title 21 Part 11, Electronic Records; Electronic Signatures",
    "source_owner": "U.S. Food and Drug Administration / Code of Federal Regulations",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["electronic records", "electronic signatures", "Part 11 scope", "record and signature controls"],
    "claim_boundary": "fda_regulatory_context_only_not_company_policy_not_validation_approval_not_product_approval_not_production_approval_not_package_authority",
    "citation_boundary": "cite as FDA or CFR current/public context only within FDA scope and stated applicability",
    "citation_label": "FDA 21 CFR Part 11 current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_regulatory_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_regulatory_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public URL, fetch behavior, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Core U.S. regulated life sciences source for electronic records and electronic signatures.",
    "limitations": ["Not company policy", "Not legal advice", "Not validation approval", "Not product approval", "Not production approval", "Not package authority", "eCFR or FDA source fetch behavior requires later verification"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "fda-part-11-scope-application-guidance-candidate",
    "title": "FDA Guidance, Part 11, Electronic Records; Electronic Signatures, Scope and Application",
    "source_owner": "U.S. Food and Drug Administration",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["Part 11 scope and application", "predicate-rule framing", "validation approach", "audit trail approach", "copies and retention approach"],
    "claim_boundary": "fda_guidance_current_thinking_only_nonbinding_unless_tied_to_applicable_law_not_company_policy_not_validation_approval_not_package_authority",
    "citation_boundary": "cite as FDA guidance current thinking only within stated guidance scope",
    "citation_label": "FDA Part 11 Scope and Application guidance current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_guidance_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_guidance_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public URL, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "FDA current-thinking guidance for Part 11 scope and application questions.",
    "limitations": ["Guidance is nonbinding unless tied to applicable statutes or regulations", "Not company policy", "Not legal advice", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "fda-computer-software-assurance-csa-candidate",
    "title": "FDA Computer Software Assurance for Production and Quality System Software guidance",
    "source_owner": "U.S. Food and Drug Administration",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["computer software assurance", "risk-based assurance", "production and quality system software assurance"],
    "claim_boundary": "fda_guidance_current_thinking_only_not_approval_of_specific_assurance_method_or_tool_not_package_authority",
    "citation_boundary": "cite as FDA CSA guidance current thinking only within stated guidance scope",
    "citation_label": "FDA Computer Software Assurance guidance current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_guidance_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_guidance_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public URL, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "FDA guidance relevant to production and quality system software assurance.",
    "limitations": ["Not approval of a specific assurance method", "Not tool approval", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "fda-qmsr-21-cfr-820-candidate",
    "title": "FDA Quality Management System Regulation / 21 CFR Part 820",
    "source_owner": "U.S. Food and Drug Administration",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["medical device quality management system", "ISO 13485 incorporation context", "QMSR transition", "inspection expectation context"],
    "claim_boundary": "fda_medical_device_regulatory_context_only_not_iso_certification_substitute_not_fda_compliance_claim_not_package_authority",
    "citation_boundary": "cite as FDA medical device regulatory current/public context only within stated scope",
    "citation_label": "FDA QMSR / 21 CFR Part 820 current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_regulatory_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_regulatory_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public URL, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "FDA medical device quality system source relevant to QMSR and 21 CFR Part 820 questions.",
    "limitations": ["Not a claim that ISO 13485 certification replaces FDA inspection", "Not a claim of FDA compliance", "Not company policy", "Not product approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "fda-ai-ml-enabled-medical-device-guidance-candidate",
    "title": "FDA AI/ML-enabled medical device guidance and action-plan sources",
    "source_owner": "U.S. Food and Drug Administration",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["AI-enabled device regulatory posture", "software change control plan context", "SaMD governance", "MLMD lifecycle expectations"],
    "claim_boundary": "fda_device_guidance_current_thinking_only_not_approval_for_specific_ai_ml_device_or_internal_ai_tool_not_package_authority",
    "citation_boundary": "cite as FDA AI/ML medical device current/public context only within stated scope",
    "citation_label": "FDA AI/ML-enabled medical device current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_time_sensitive_guidance_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_time_sensitive_guidance_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact stable FDA source, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "FDA source group relevant to AI-enabled medical device and SaMD governance.",
    "limitations": ["Not approval for a particular AI/ML device", "Not approval for an internal AI tool", "Not company policy", "Not product approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "eu-gmp-annex-11-computerised-systems-candidate",
    "title": "European Commission EudraLex Volume 4, Annex 11: Computerised Systems",
    "source_owner": "European Commission EudraLex Volume 4",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["GMP computerised systems", "validation", "data integrity", "audit trails", "security", "business continuity", "supplier and service-provider controls"],
    "claim_boundary": "eu_gmp_guidance_context_only_for_medicinal_products_not_global_policy_by_itself_not_package_authority",
    "citation_boundary": "cite as EU GMP current/public context only within EudraLex stated scope",
    "citation_label": "EU GMP Annex 11 current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public EudraLex URL, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "EU GMP source for computerised systems, validation, data integrity, and audit trail governance.",
    "limitations": ["EU GMP guidance for medicinal products", "Not global policy by itself", "Not company SOP", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "eu-gmp-chapter-4-documentation-candidate",
    "title": "EudraLex Volume 4 Chapter 4, Documentation",
    "source_owner": "European Commission EudraLex Volume 4",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["GMP documentation", "records", "data integrity", "document control"],
    "claim_boundary": "eu_gmp_guidance_context_only_not_company_specific_gdp_gdocp_sop_not_package_authority",
    "citation_boundary": "cite as EU GMP documentation current/public context only within EudraLex stated scope",
    "citation_label": "EU GMP Chapter 4 Documentation current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public EudraLex URL, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "EU GMP source for documentation, records, data integrity, and document-control context.",
    "limitations": ["Not company-specific GDP or GDocP SOP", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "ema-computerised-systems-gcp-gxp-guidance-candidate",
    "title": "EMA computerised systems / clinical systems / data integrity guidance",
    "source_owner": "European Medicines Agency",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_regulatory_source",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["clinical computerized-system expectations", "regulated computerized-system expectations", "data integrity context where applicable"],
    "claim_boundary": "ema_guidance_within_stated_scope_only_not_company_policy_not_validation_approval_not_package_authority",
    "citation_boundary": "cite as EMA current/public context only within stated source scope",
    "citation_label": "EMA computerised systems / GxP current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_guidance_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_guidance_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact EMA source, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "EMA source group relevant to clinical systems, computerized systems, and data integrity where applicable.",
    "limitations": ["Exact source and scope require later verification", "Not global policy by itself", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "ich-q9-quality-risk-management-candidate",
    "title": "ICH Q9(R1) Quality Risk Management",
    "source_owner": "International Council for Harmonisation",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_harmonized_guideline",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["quality risk management principles", "risk-based validation framing", "risk-based assurance framing"],
    "claim_boundary": "ich_harmonized_guidance_context_only_not_implementation_approval_not_package_authority",
    "citation_boundary": "cite as ICH harmonized quality guidance current/public context only within stated guideline scope",
    "citation_label": "ICH Q9(R1) current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_version_bound_guideline_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_version_bound_guideline_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact ICH source, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Harmonized quality risk management guidance relevant to risk-based validation and assurance framing.",
    "limitations": ["Not implementation approval", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "ich-q10-pharmaceutical-quality-system-candidate",
    "title": "ICH Q10 Pharmaceutical Quality System",
    "source_owner": "International Council for Harmonisation",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_harmonized_guideline",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["pharmaceutical quality system model", "lifecycle framing", "knowledge management", "continual improvement"],
    "claim_boundary": "ich_harmonized_guidance_context_only_not_company_qms_approval_not_package_authority",
    "citation_boundary": "cite as ICH harmonized quality guidance current/public context only within stated guideline scope",
    "citation_label": "ICH Q10 current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_version_bound_guideline_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_version_bound_guideline_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact ICH source, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Harmonized pharmaceutical quality system guidance relevant to lifecycle and continual improvement questions.",
    "limitations": ["Not company QMS approval", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "ich-e6-good-clinical-practice-candidate",
    "title": "ICH E6 Good Clinical Practice",
    "source_owner": "International Council for Harmonisation",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_harmonized_guideline",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["clinical trial quality", "sponsor and investigator responsibilities", "essential documents", "computerized clinical systems where relevant"],
    "claim_boundary": "ich_clinical_research_guidance_context_only_not_manufacturing_qms_or_medical_device_qms_authority_not_package_authority",
    "citation_boundary": "cite as ICH clinical research guidance current/public context only within stated guideline scope",
    "citation_label": "ICH E6 current/public context",
    "freshness_review_cadence": "verify_exact_public_source_and_applicable_revision_before_enablement_then_version_bound_guideline_review",
    "review_cadence": "verify_exact_public_source_and_applicable_revision_before_enablement_then_version_bound_guideline_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact ICH source, applicable revision, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Harmonized clinical research guidance relevant to clinical systems and trial-record questions.",
    "limitations": ["Clinical research guidance", "Not manufacturing QMS authority", "Not medical-device QMS authority", "Not company policy", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "iso-13485-standard-metadata-candidate",
    "title": "ISO 13485:2016 official metadata / FDA QMSR incorporation-by-reference references / ANSI IBR portal references",
    "source_owner": "ISO / FDA / ANSI incorporated-by-reference metadata owners",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_standard_metadata",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["medical device QMS standard identity", "high-level applicability metadata"],
    "claim_boundary": "standard_metadata_only_not_full_text_not_substitute_for_standard_not_package_authority",
    "citation_boundary": "cite only official public metadata or legally accessible incorporated-by-reference pages unless full text is legally available",
    "citation_label": "ISO 13485 metadata current/public context",
    "freshness_review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms official public metadata, legal access posture, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Medical device quality management system standard identity and applicability metadata.",
    "limitations": ["Metadata only unless full text is legally accessible", "Do not reproduce paywalled standard text", "Not a substitute for the standard", "Not company QMS approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences standards metadata candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "iso-14971-standard-metadata-candidate",
    "title": "ISO 14971 official metadata / recognized standard references",
    "source_owner": "ISO / recognized standards metadata owners",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_standard_metadata",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["medical device risk management standard identity", "high-level scope metadata"],
    "claim_boundary": "standard_metadata_only_not_full_text_not_substitute_for_standard_not_package_authority",
    "citation_boundary": "cite only official public metadata or recognized-standard references unless full text is legally available",
    "citation_label": "ISO 14971 metadata current/public context",
    "freshness_review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms official public metadata, legal access posture, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Medical device risk management standard identity and scope metadata.",
    "limitations": ["Metadata only unless full text is legally accessible", "Do not reproduce paywalled standard text", "Not a substitute for the standard", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences standards metadata candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "iec-62304-standard-metadata-candidate",
    "title": "IEC 62304 official metadata / recognized standard references",
    "source_owner": "IEC / recognized standards metadata owners",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_standard_metadata",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["medical device software lifecycle standard identity", "high-level scope metadata"],
    "claim_boundary": "standard_metadata_only_not_full_text_not_substitute_for_standard_not_package_authority",
    "citation_boundary": "cite only official public metadata or recognized-standard references unless full text is legally available",
    "citation_label": "IEC 62304 metadata current/public context",
    "freshness_review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms official public metadata, legal access posture, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Medical device software lifecycle standard identity and scope metadata.",
    "limitations": ["Metadata only unless full text is legally accessible", "Do not reproduce paywalled standard text", "Not a substitute for the standard", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences standards metadata candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "iec-82304-1-health-software-standard-metadata-candidate",
    "title": "IEC 82304-1 official metadata / recognized standard references",
    "source_owner": "IEC / recognized standards metadata owners",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_standard_metadata",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["standalone health software product safety and security lifecycle context", "high-level scope metadata"],
    "claim_boundary": "standard_metadata_only_not_full_text_not_substitute_for_standard_not_package_authority",
    "citation_boundary": "cite only official public metadata or recognized-standard references unless full text is legally available",
    "citation_label": "IEC 82304-1 metadata current/public context",
    "freshness_review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "review_cadence": "verify_exact_public_metadata_or_legal_access_before_enablement_then_version_bound_standard_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms official public metadata, legal access posture, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Standalone health software product standard identity and scope metadata.",
    "limitations": ["Metadata only unless full text is legally accessible", "Do not reproduce paywalled standard text", "Not a substitute for the standard", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences standards metadata candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "ispe-gamp5-candidate",
    "title": "ISPE GAMP 5 and related public pages / metadata",
    "source_owner": "International Society for Pharmaceutical Engineering",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_industry_guidance",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["computerized system validation and assurance good-practice framing", "risk-based approach", "supplier assessment", "lifecycle controls"],
    "claim_boundary": "industry_guidance_not_regulation_not_company_policy_not_validation_approval_not_package_authority",
    "citation_boundary": "cite as industry good-practice context only and do not reproduce licensed text",
    "citation_label": "ISPE GAMP 5 metadata current/public context",
    "freshness_review_cadence": "verify_public_metadata_or_licensed_access_before_enablement_then_periodic_industry_guidance_review",
    "review_cadence": "verify_public_metadata_or_licensed_access_before_enablement_then_periodic_industry_guidance_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms public metadata or legal access, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Widely used regulated-industry good-practice source for computerized system validation and assurance framing.",
    "limitations": ["Industry guidance, not regulation", "Do not reproduce licensed text", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences industry-guidance candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "pics-gmp-data-integrity-guidance-candidate",
    "title": "PIC/S GMP data integrity guidance",
    "source_owner": "Pharmaceutical Inspection Co-operation Scheme",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_inspectorate_guidance",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["data integrity", "records", "audit trails", "governance expectations"],
    "claim_boundary": "pics_inspectorate_guidance_within_stated_scope_only_not_company_policy_not_validation_approval_not_package_authority",
    "citation_boundary": "cite as PIC/S inspectorate guidance current/public context only within stated scope",
    "citation_label": "PIC/S GMP data integrity current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public source, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Inspectorate/cooperation-scheme guidance relevant to GMP data integrity and records governance.",
    "limitations": ["Inspectorate/cooperation scheme guidance within stated scope", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences inspectorate-guidance candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  },
  {
    "id": "who-gmp-data-integrity-guidance-candidate",
    "title": "WHO GMP / data integrity guidance",
    "source_owner": "World Health Organization",
    "source_class": "regulated_life_sciences_gxp_medical_device_authority",
    "source_type": "regulated_life_sciences_global_health_guidance",
    "proposed_url": "to_be_verified",
    "url": "to_be_verified",
    "allowed_origin": "to_be_verified",
    "allowed_path_prefix": "to_be_verified",
    "allowed_use": ["global pharma GMP reference", "data integrity reference where applicable"],
    "claim_boundary": "who_guidance_within_stated_scope_only_not_company_policy_not_validation_approval_not_package_authority",
    "citation_boundary": "cite as WHO GMP or data integrity current/public context only within stated source scope",
    "citation_label": "WHO GMP / data integrity current/public context",
    "freshness_review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "review_cadence": "verify_exact_public_source_before_enablement_then_periodic_gmp_review",
    "approval_status": "candidate_only",
    "retrieval_enabled": false,
    "approved_by": "not_approved",
    "approver": "not_approved",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "owner_approver": "life_sciences_regulatory_owner_review_required",
    "initial_posture": "candidate_deferred_url_verification_required",
    "enablement_recommendation": "Defer until a separate verification issue confirms exact public WHO source, source owner approval, path scope, and production smoke.",
    "reason_for_inclusion": "Global pharma GMP and data integrity guidance source group relevant where applicable.",
    "limitations": ["WHO guidance within stated scope", "Not company policy", "Not validation approval", "Not package authority"],
    "verification_status": "url_to_be_verified_before_candidate_fetch",
    "notes": "Regulated life sciences global-guidance candidate-only source. This is not approved package authority and not production configuration.",
    "production_enablement_allowed_in_this_ticket": false,
    "package_authority_allowed": false,
    "neutral_governance_authority_allowed": false,
    "community_authority_allowed": false,
    "user_url_retrieval_allowed": false,
    "browser_side_fetch_allowed": false,
    "arbitrary_web_search_allowed": false
  }
]
