Executive summary
Hiro now has one durable autonomous workflow that advances safe external ideas through local corroboration, frozen specification, bounded candidate construction, public and held-out evaluation, Stage 6C probation, and an explicit terminal outcome.
The workflow is append-only, idempotent, lease-protected, restart-safe, retry-aware, and monitored for nonterminal records without an executable next action.
The exact Stage 6C behavior-fragment policy was revalidated on the final implementation revision and activated for one eight-hour window. Per-candidate user approval is disabled inside that narrow policy, while post-action reporting remains required.
Live execution exposed a final-checkpoint boundary defect before retention. The active candidate was failed closed, exact prechange bytes were restored, and the lineage reached a real rolled-back terminal outcome. A second concurrent candidate was also rolled back during maintenance quiescence.
The next authority-and-rollback candidate exposed a second timing defect: a long evaluation allowed the workflow's original tick timestamp to precede actual candidate application, making a checkpoint early. That candidate was also rolled back with exact restoration, and transition timestamps are now refreshed after long-running work.
The final revision passed 498 repository tests and a fresh exact-revision campaign, the eight-hour policy was reactivated, and Hiro restarted cleanly. All 10 known lineages are now terminal with zero stuck records; the scheduler is ready to advance newly discovered safe ideas.