No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →Project Trust and Instruction Authority
Bind explicit trust to a stable workspace identity and decide which project inputs may become instructions instead of ordinary untrusted data.
What feeds it, and what does it unlock?
Arrows show learning and design dependencies, not runtime data flow. Follow any node to continue through the Atlas.
Bind explicit trust to a stable workspace identity and decide which project inputs may become instructions instead of ordinary untrusted data.
The structured record is in the Atlas, but the L0–L4 article has not passed content review.
Snapshot implementations
An implementation enters the map only when both a snapshot and claims exist; unknowns remain visible.
No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →The teaching-harness reference does not automatically become an architectural claim about any vendor agent.
What has actually been tested?
Formal experiments are separate from course exercises. Exercises can validate the reference implementation but cannot replace Native evidence from a real agent.
Platform/project sources are accepted while external/tool-output sources are quarantined outside the system prompt.
python3 -m curriculum.golden verify s12-project-trustChanging revision changes the fingerprint and does not inherit the old grant; keyword detection does not change authority.
python3 -m unittest curriculum.tests.test_vertical_slice.VerticalSliceTests.test_s12_keeps_untrusted_data_out_of_instruction_authority -vWhich repository changes should invalidate an existing trust grant?
How should nested projects and dependency worktrees compose instruction authority?
Which prompt-injection signals are useful for review without being mistaken for enforcement?