5a9a2ae05c
Two roll-ups were vacuously satisfiable by a no-op and guarded only in agent prose, never re-verified at the consuming gate: - The milestone-close functional leg trusted a fieldtest `clean` roll-up even from a run with zero examples. The gate now requires examples_added >= 2 for a `clean` to be honoured (the empty-report and internal-milestone escapes are preserved); a `clean` with fewer over user-visible surface is itself a `spec_gap`. - The audit carry-on accepted an architect `clean` with no evidence of review. It now requires a non-empty "What holds" (added as an explicit handoff field); a bare `clean` with nothing held — worst when no regression scripts run, so the architect is the sole gate — reads as unreviewed and is re-dispatched. Both are second-layer checks: the consumer verifies the field rather than trusting the agent's discipline. Lower-severity defense-in-depth, not code-level floors (milestone-close and audit carry-on are orchestrator-judgment acts with no script to instrument). closes #14