HL01Authority receipt
Question: Who authorized this action, for what purpose, scope, jurisdiction and time?
Machine fields: authority_id, issuer, scope, purpose, jurisdiction, valid_until, revocation_state
Avoid: Showing a green check without the source or scope of authority.
HL02Evidence provenance card
Question: What was observed, by whom, when, through which method, and what changed afterward?
Machine fields: evidence_id, epistemic_type, source, method, observed_at, lineage, integrity_state
Avoid: Presenting an interpretation as raw observation.
HL03Uncertainty and missing-data strip
Question: What is unknown, unavailable, not checked or disputed?
Machine fields: unknown_state, missing_fields, assumptions, confidence, counterevidence
Avoid: Replacing unknown values with reassuring defaults.
HL04Version and change badge
Question: Which version/revision is this, and has a material field changed?
Machine fields: artifact_id, publisher_revision, observed_at, comparison_status, changed_fields
Avoid: Calling a selected-field digest a raw response hash.
HL05Partition state banner
Question: Is the system disconnected, in minimum function, or awaiting reconciliation?
Machine fields: partition_state, last_contact, minimum_functions, prohibited_actions, sunset
Avoid: Using a generic offline icon while silently widening authority.
HL06Stay and revocation banner
Question: What is frozen or revoked, by whom, until when, and what remains permitted?
Machine fields: stay_id, scope, issuer, reason, effective_at, expiry, exceptions
Avoid: Hiding a stay in audit logs while the visible UI still suggests authority.
HL07Restoration ledger
Question: Which records and decisions were corrected, who acknowledged, and what cannot be repaired?
Machine fields: restoration_id, affected_records, derivative_decisions, recipients, acknowledgements, residual_harm
Avoid: Declaring restoration complete after changing only the source record.
HL08Source-independence label
Question: Is this first-party, reciprocal, independent, legal, standards-based or empirical evidence?
Machine fields: source_role, root_source, claim_scope, period, independence_class
Avoid: Counting republications as independent corroboration.
HL09Synthetic/operational status badge
Question: Is this a definition, static record, synthetic execution, live observation or independent review?
Machine fields: result_class, operational, synthetic, persisted, external_command, certification
Avoid: Displaying a synthetic PASS without the synthetic/non-operational boundary.
HL10Reviewer independence card
Question: Who reviewed, under what mandate, and were conflicts or recusals recorded?
Machine fields: reviewer_role, mandate, independence_basis, conflicts, recusal, disposition
Avoid: Equating a second person or model with independent review.
HL11Reason-code explainer
Question: What happened, why, what evidence class was used, and what can the reader do next?
Machine fields: reason_code, plain_language_reason, evidence_class, authority, next_action, appeal_route
Avoid: Providing only an opaque code or only persuasive narrative.
HL12Downstream correction receipt
Question: Where did the original claim travel, which targets changed, and which remain pending?
Machine fields: correction_id, prior_state, corrected_state, propagated_targets, pending_targets, receipts
Avoid: Treating local correction as global propagation.
HL13Conjunctive gate panel
Question: Which hard gate failed, and why can success elsewhere not compensate?
Machine fields: gate_ids, gate_results, hard_failures, final_state, non_compensability
Avoid: Reducing authority, evidence and recovery to one readiness percentage.
HL14Unknown-preserving result card
Question: Was the property supported, partial, contradicted, unavailable or not observed?
Machine fields: property_id, artifact_id, result, observed_statement, not_established, review_condition
Avoid: Forcing every absence into pass or fail.
HL15Baseline lineage card
Question: What exact baseline and target were compared, and were they actually comparable?
Machine fields: lineage_id, source_release, target_release, comparison_boundary, prior_sha256, current_sha256, result, limitations
Avoid: Fluent summary, badge, or aggregate score hides a material machine state, unknown, conflict, or invalidation.
HL16Material change receipt
Question: Which dimensions changed, who judged materiality, and which dependencies are affected?
Machine fields: difference_set, material_dimensions, review_authority, rationale, dependent_record_ids, invalidation_state
Avoid: Fluent summary, badge, or aggregate score hides a material machine state, unknown, conflict, or invalidation.
HL17Restoration proof checklist
Question: Which mandatory obligations pass, fail, or remain unknown before limited or full restoration?
Machine fields: profile_id, obligation_results, blocking_obligations, target_state, maximum_safe_state
Avoid: Fluent summary, badge, or aggregate score hides a material machine state, unknown, conflict, or invalidation.
HL18Contested history panel
Question: Which histories agree, conflict, or remain unavailable, and what state is safe while unresolved?
Machine fields: history_ids, common_facts, contested_facts, unknowns, resolution_state, maximum_safe_state
Avoid: Fluent summary, badge, or aggregate score hides a material machine state, unknown, conflict, or invalidation.
HL19Invalidation propagation notice
Question: Which prior result became invalid and which claims, decisions, receipts, or caches require review?
Machine fields: trigger_id, invalidated_record_ids, dependent_record_ids, acknowledgements, revalidation_route
Avoid: Fluent summary, badge, or aggregate score hides a material machine state, unknown, conflict, or invalidation.
HL20Reproducible local run record
Question: What exact local artifacts, script, checks, results, and limitations support this run?
Machine fields: run_id, script_sha256, input_sha256, check_results, run_status, limitations
Avoid: Fluent summary, badge, or aggregate score hides a material machine state, unknown, conflict, or invalidation.