Provider slots
Three read-only slot cards: Bound, Unbound, Error. Fail-closed when unbound or error. Typed throttles in receipt. Not live masterengine.ai. Not kernel source of truth.
Fail-closed attest policy
- Bound may show ready only from mock fixture binding claims — never a live provider handshake.
- Unbound and Error are fail-closed: not ready, no pretend-ready, no greenwash.
- Typed throttles:
slow_down(HTTP 429) vsserver_is_overloaded(HTTP 503) — distinct; never collapsed. Retry-Afteris first-class receipt evidence when present in the fixture.- Env key names only (see
env.example). Secret values never ship in this pack. - Offline mock JSON only. No Responses client, Assistants, Sora, or live egress.
Ready count —
Fail-closed count —
Typed throttle placeholders
- Awaiting local fixture…
Awaiting local fixture…