UC-09 · Group B — Level 1 · Semantic Governance
Preparation is not release
Running the computation and releasing its output are two separate approvals, held by two separate roles.
A bespoke derivation running inside the trusted boundary as a ProtectedExecutionRecord, then its ReleaseCandidate inspected separately — with the output coarsened before it leaves.
Protected execution approval does not imply release approval — and inspect-and-release is the one reserved Level 1 inline placement, not the default topology.
Canned ProtectedExecutionRecord and ReleaseCandidate objects (the request-protected-subgraph-execution and inspect-release-candidate endpoints exist for live garnish) show ReleaseInspectionStatus: PATCH_AND_ALLOW with two distinct approvals by two distinct roles.
“The computation was allowed. The output was not.”