Q1 classification trust: model (C) — caller declares, server cross-checks target tag, stricter wins, mismatch logged. Needs a classification taxonomy + per-wing/repo tags (prerequisite, sub-task of #49). Q2 harness origin: server-derived from authenticated principal; context.harness is descriptive-only, never a gate input. Q3 central relay: ships in v1 (needed for claude.ai/Crush/Pi/LLM Council) + I2 security-baseline ledger entry is v1 work. Q4 audit-sink-down: degrade-and-warn + durable local buffer + reconcile on recovery; refuse only if NOTHING can record the audit. Updated the I1 sovereignty + I5 auditability Gherkin scenarios to match; added classification-mismatch and origin-spoofing scenarios.