# Context Canvas public-reference materialization settlement

## Desired state

Context Canvas source remains useful to a collaborator without embedding a
mutable workspace route in durable public-possible history. Stable semantic
keys preserve the reader job and receiving identity. An authorized build
supplies the reviewed destination and emits ordinary static links for visitors.

The public-possible workspace boundary covers the approved source family and
its descendants. Authored Context Canvas HTML carries no direct workspace page
route, including a route that may later become public. Private lineage remains
recoverable through the authorized resolver.

## Settled source and build contract

- Complete anchor `href` values and token-bearing JSON-LD strings carry one
  `PUBLIC_URL_REGISTRY_*` key per semantic receiver.
- The shared footer script carries the exact
  `PUBLIC_URL_AUTHOR_PROFESSIONAL_PROFILE` key once. Local source presents a
  useful availability label; a configured build presents the ordinary profile
  link with its descriptive accessible name.
- Visible link text and neighboring explanation keep the unmaterialized source
  orienting; the generated artifact supplies navigation to the external route.
- Required keys are discovered from authored HTML and the one approved shared
  script carrier. No separate route manifest, ancestry registry, or recurring
  workspace census owns that truth.
- Ignored `.env.public` values or matching process-environment values supply
  human-approved credential-free HTTPS destinations.
- The materializer rejects URL userinfo and recognized credential-bearing query
  or fragment parameters without printing configured values. Human review owns
  path-shaped access coordinates and unfamiliar signing conventions.
- The dependency-free Node 22 materializer copies the
  `context-canvas-project-surface/` subtree, transforms approved Context Canvas
  HTML carriers and the shared footer-script carrier in a temporary sibling
  generation, validates every accepted carrier, and then replaces only an
  output generation bearing its ownership marker.
- A configuration or validation failure leaves the prior accepted generation
  available. Diagnostics carry semantic keys and safe paths while destination
  values remain in their configured receiver.
- Every copied regular file is scanned for direct Notion routes, and build
  configuration remains outside the copied source tree. An exceptional
  filesystem restore failure preserves its ignored recovery directory rather
  than discarding the prior generation.
- The generated subtree is a materialized build input. A future publication
  assembler still owns adjacent repository dependencies, audience selection,
  upload, and recovery.

## Hosted iframe receiver transition

The HEART carrier first proved the late-bound iframe twin seam through
`PUBLIC_URL_IFRAME_CORE_HEART_CHART`. That seam established the distinction
between a hosted iframe destination and its repository-local full view before
the public receiver was active.

The receiver is now active and its versioned Core routes are stable. Current
authored carriers therefore use manifest-owned
`https://iframes.vik.guru/v1/core/.../` values directly in `src`, while their
adjacent full-view anchors continue to open the current Context Canvas
prototype under `prototypes/...`. The HEART-only configuration key and data
attributes are retired. The generic twin seam remains covered by focused
materializer tests for a future receiver that is genuinely late-bound.

Nine iframe instances currently use eight hosted routes. Each declares the
exact sandbox and Permissions Policy recorded by its route profile. The Core
pack index is not embedded: it opens as a full-view navigation surface so a
visitor can enter each sibling prototype without making the index carrier hold
the union of every reachable capability. The additional route carries the
Conditioning Field as a supplemental Context Canvas source with a generated
single-file receiver; its adjacent full-view route remains local.

## Evidence and evidence boundary

The migration began with a bounded set of workspace identities across anchor
and JSON-LD occurrences in the Context Canvas HTML family. That observation
established the initial scope and confirmed one shared semantic-key family.
The runnable check now discovers the live public-reference and
professional-profile key set from source, exercises a complete synthetic
materialization, parses only token-bearing JSON-LD, and confirms that authored
input and activated iframe destinations remain unchanged.

The build establishes deterministic substitution, context-appropriate escaping,
and retained-generation recovery. It does not establish Registry ancestry,
content standing, signed-out availability, or publication authority. The
private resolver and human observation supply those receipts.

The exact proposed-index comparison returned ready in no-additions mode. It
observed zero tracked workspace-platform route occurrences, with no additions
in any other scoped locator family. Strict successor readiness remains with the
established public-baseline chain because the retained repository still carries
earlier first-party GitHub routes and repository coordinates outside this
materializer's contract.

## Receiver sequence

The retained-source implementation is the current front for
`work:late-bound-public-route-receiver`. Its review-ready return consists of the
semantic source change, materializer, focused tests, documentation, and a
locator-safe pull-request receipt.

After acceptance:

1. the successor snapshot collaborator re-forms the first population commit
   from the accepted source and re-pins its revision-link settlement;
2. the successor's strict boundary receipt observes a locator-free candidate;
3. this session verifies that the successor received the materializer contract,
   ignored configuration boundary, tests, and nearest documentation intact;
4. the successor-owned Core and Narrative baseline becomes the next
   stabilization front; and
5. the first authorized documentation or Context Canvas delivery forms one
   focused receiver for configuration injection, pre-upload materialization,
   complete asset closure, and delivery evidence.

The standing Field Inspection pilot keeps its authored-byte parity. Its first
real shared delivery can select materialize-then-assemble or
assemble-then-materialize as one explicit composition seam.

## Skill return

Repository re-entry, source-authority mapping, locator-boundary stewardship,
issue-chain stewardship, stateful-artifact behavior contracts, and Supportive
Change Writing carried this wave without an unowned collaboration job.
Collaboration accounting therefore keeps
`externalized-reference-materialization` at **observe / hold**. The existing
skills need no revision from this first receiver.

Return to that candidate after a second materially different artifact family or
the first actual successor delivery exposes a transferable decision that the
current skill composition does not already carry. This keeps skill cultivation
responsive to material use rather than making the materializer wait for a new
authority layer.

## Re-entry

Re-enter at the materializer's nearest README and test before changing build
behavior. The professional-profile destination remains in ignored local or
delivery configuration and is ready for the production assembler’s eventual
materialize-then-select seam. Reopen delivery architecture when a named public
receiver owns a complete asset closure and approved configuration. Reopen
runtime routing when instant rotation, vanity paths, contextual fallback,
access observation, or an authenticated synchronization job creates a visitor
or operator benefit that a rebuild cannot supply.
