Enforcement map
Generated by bash gate-sdk/bin/run-gates.sh --emit enforcement-map; do not
hand-edit — check-enforcement-fresh byte-compares this page against the
emitter.
Every governed surface in this repo is held by one enforcement class, ordered
here from hardest to softest:
The rows below derive from the class registries — the gate registry, the KPI
registry, the harness settings hooks, the evidence-suite config, and the
# enforce: markers a non-gate surface declares itself with — so this map
cannot drift from what actually runs. A registry a consumer has not adopted
leaves its section absent.
Blocking gates
| kit |
gate |
tier |
| gate-sdk |
check-shellcheck |
precommit |
| gate-sdk |
check-gate-output |
precommit |
| gate-sdk |
check-gate-fail-closed |
precommit |
| gate-sdk |
check-gate-fixture-coverage |
precommit |
| gate-sdk |
check-gate-exemption-tasks |
precommit |
| gate-sdk |
check-gate-substrate-parity |
precommit |
| gate-sdk |
check-gate-binary-fresh |
precommit |
| gate-sdk |
check-crate-arms |
precommit |
| gate-sdk |
check-install-disposition |
precommit |
| gate-sdk |
check-test-hermetic |
precommit |
| gate-sdk |
check-assertion-strength |
precommit |
| gate-sdk |
check-graph |
precommit |
| gate-sdk |
check-reads-couples |
precommit |
| gate-sdk |
check-kit-enum |
precommit |
| gate-sdk |
check-kit-registration |
precommit |
| gate-sdk |
check-readme-roster |
precommit |
| gate-sdk |
check-smoke-entry-guard |
precommit |
| (consumer) |
check-docs-kit-parity |
precommit |
| (consumer) |
check-docs-nav-reachable |
precommit |
| doctrine-kit |
check-doctrine-registration |
precommit |
| lifecycle-kit |
check-lifecycle-registration |
precommit |
| (consumer) |
check-kit-ref-liveness |
precommit |
| (consumer) |
check-trajectory-fresh |
precommit |
| context-kit |
check-footprint-fresh |
precommit |
| (consumer) |
check-docs-mirror-fresh |
precommit |
| gate-sdk |
check-enforcement-fresh |
precommit |
| (consumer) |
check-value-rollup-fresh |
precommit |
| gate-sdk |
check-hook-exec-bit |
precommit |
| gate-sdk |
check-exec-bit |
precommit |
| gate-sdk |
check-tree-terms |
precommit |
| gate-sdk |
check-root-tiering |
precommit |
| gate-sdk |
check-workflow-tiering |
precommit |
| gate-sdk |
check-action-pinning |
precommit |
| gate-sdk |
check-action-run-shell |
precommit |
| gate-sdk |
check-action-gh-repo |
precommit |
| gate-sdk |
check-action-permissions |
precommit |
| gate-sdk |
check-core-files |
precommit |
| gate-sdk |
check-identity |
precommit |
| lifecycle-kit |
check-stage-evidence |
precommit |
| lifecycle-kit |
check-stage-entry |
precommit |
| lifecycle-kit |
check-stage-skill-coverage |
precommit |
| lifecycle-kit |
check-skill-binding |
precommit |
| lifecycle-kit |
check-shim-restatement |
precommit |
| lifecycle-kit |
check-lesson-disposition |
precommit |
| lifecycle-kit |
check-merge-attrs |
precommit |
| lifecycle-kit |
check-close-surfaces |
precommit |
| lifecycle-kit |
check-survey-record |
precommit |
| lifecycle-kit |
check-scratch-citation |
precommit |
| lifecycle-kit |
check-gap-inbox-neutrality |
precommit |
| queue-kit |
check-queue-sections |
precommit |
| queue-kit |
check-queue-hygiene |
precommit |
| queue-kit |
check-queue-wrap |
precommit |
| queue-kit |
check-tag-lead-line |
precommit |
| queue-kit |
check-queue-entry-budget |
precommit |
| queue-kit |
check-task-names |
precommit |
| queue-kit |
check-task-conservation |
precommit |
| queue-kit |
check-queue-prose-precondition |
precommit |
| queue-kit |
check-queue-slug-liveness |
precommit |
| queue-kit |
check-roadmap-fresh |
precommit |
| canon-kit |
check-amendment-queue |
precommit |
| canon-kit |
check-amendment-update-target |
precommit |
| canon-kit |
check-spec-embedded-source |
precommit |
| canon-kit |
check-spec-fence-balance |
precommit |
| canon-kit |
check-md-refs |
precommit |
| canon-kit |
check-docs-link-convention |
precommit |
| site-kit |
check-docs-cname-parity |
precommit |
| site-kit |
check-docs-render-fidelity |
precommit |
| canon-kit |
check-docs-cmd |
precommit |
| (consumer) |
check-install-toolchain |
precommit |
| canon-kit |
check-install-claim |
precommit |
| canon-kit |
check-payload-claim |
precommit |
| (consumer) |
check-installer-no-deps |
precommit |
| (consumer) |
check-release-bump |
precommit |
| (consumer) |
check-release-channel-parity |
precommit |
| (consumer) |
check-tightened-gates-grammar |
precommit |
| (consumer) |
check-tightened-gates-note-parity |
precommit |
| (consumer) |
check-npm-publish-spec |
precommit |
| canon-kit |
check-manifest-temporal |
precommit |
| canon-kit |
check-manifest-count |
precommit |
| canon-kit |
check-measured-claim |
precommit |
| canon-kit |
check-unmarked-claim |
precommit |
| canon-kit |
check-tracking-claim |
precommit |
| canon-kit |
check-prose-enum |
precommit |
| canon-kit |
check-prose-tells |
precommit |
| canon-kit |
check-knob-citation |
precommit |
| canon-kit |
check-knob-default-coupling |
precommit |
| canon-kit |
check-comment-tier |
precommit |
| canon-kit |
check-spec-pointer |
precommit |
| canon-kit |
check-todo-task-liveness |
precommit |
| canon-kit |
check-deprecation-task |
precommit |
| evidence-kit |
check-evidence-baseline |
precommit |
| evidence-kit |
check-evidence-manifest |
precommit |
| evidence-kit |
check-battery-roster |
precommit |
| delegation-kit |
check-gate-tamper |
precommit |
| delegation-kit |
check-rule-citation |
precommit |
| delegation-kit |
check-agent-tier-explicit |
precommit |
| context-kit |
check-brevity |
precommit |
| context-kit |
check-settings-pins |
precommit |
| context-kit |
check-settings-paths |
precommit |
| context-kit |
check-memory-off |
precommit |
| gate-sdk |
check-template-copy-parity |
precommit |
| gate-sdk |
check-template-registry-parity |
precommit |
| gate-sdk |
check-commit-msg |
commit-msg |
| gate-sdk |
check-commit-subject |
commit-msg |
| gate-sdk |
check-gate-assertions |
align-only |
| canon-kit |
check-spec-dod-singleton |
align-only |
| canon-kit |
check-spec-derivable-section |
align-only |
Advisory KPIs
Guards
| kit |
surface |
intercepts |
| (consumer) |
scripts/bash-guard.sh |
Bash |
| (consumer) |
scripts/agent-budget-guard.sh |
Agent |
| (consumer) |
scripts/agent-dispatch-guard.sh |
Agent |
| (consumer) |
scripts/workflow-state-guard.sh |
Write|Edit |
Session warnings
| kit |
surface |
| (consumer) |
scripts/session-context.sh |
Validate suites
Monitors
| kit |
surface |
| (consumer) |
live docs-site deployment — apex/www/http HTTPS, redirects, cert expiry, release-body note pointers, and each published Release’s prerelease flag against its own version line |