{
  "surveillanceSchemaVersion": "1.0",
  "systemId": "definitive-flash",
  "classification": {
    "current": null,
    "label": "Unclassified",
    "status": "insufficient-evidence-for-exposure-class"
  },
  "cadence": {
    "signedExecutionSafety": "weekly"
  },
  "evidencePolicy": {
    "scheduledObservations": "committed JSON plus GitHub Actions artifact",
    "upstreamPinning": "each observation records the exact Definitive Flash MCP upstream commit",
    "currentLimitation": "surveillance re-tests deterministic upstream signed-execution suites and fake-client reconciliation rather than live trading or production API authorization",
    "dependencyNote": "the pinned upstream commit has a package.json override not reflected in bun.lock; installs use the pinned manifest with --no-save and reject metadata mutation",
    "productionCertification": false,
    "exposureClassEffect": "none until stronger authorization, revocation, limit, custody and live-execution evidence exists"
  },
  "latestEndpoints": {
    "signedExecutionSafety": "/data/agent-risk-graph/surveillance/definitive-flash/latest/signed-execution-safety.json"
  }
}
