# Lane ledger contract

Append one structured event per lifecycle step in the assigned lane. The ledger indexes evidence; Native dispatch and Git custody remain authoritative.

## Required header

```yaml
schema: shepherd.lane-ledger/1
run: <run-id>
lane: <lane-id>
outcome: <measurable outcome>
owner: <one Conductor identity>
baseline_commit: <full commit>
plan_digest: <sha256>
skill_bundle_digest: <sha256>
status: ready|running|reviewing|redo|blocked|accepted|handed-off
```

## Required event fields

Every event: `event_id`, `node_id`, `role`, `work_kind`, `read_scope`, `write_scope`, `task_digest`, `dispatch_id`, `result_artifact`, `review_artifact`, `command`, `exit_status`, `semantic_result`, `evidence_digest`, `recorded_at`, `next_action`.
Mutation adds worktree/output commit; retry adds `retry_of`, finding, bounded predicate and re-review; escalation adds route, reason, preserved evidence and parent response.

For root-owned verification, correlate `gate-request`/`gate-result` with run/node/dispatch/task, worktree/source snapshot, command/environment, expected predicate, root executor, actual exit and raw output hashes. Use native host messaging, not a notification registry or Native gate API. Read matching RED before releasing Coder for production edits. Changed inputs need a new request; root never supplies source edits.

## Acceptance record

Require final reviewed commit/path manifest, independent Auditor evidence with no unresolved Critical/Important finding, real RED/GREEN status and semantic results, startup skill/bundle digest, risks/rollback/restart and independently verifiable handoff.
After review/gate, mark `accepted`, then `handed-off`; parent owns integration. Missing fields, drift, stale evidence or post-review mutation require `redo`/`blocked`.

Native terminal custody is part of acceptance: a Coder or Worker result must parse as its
role-bound typed result with non-empty evidence, and the allocated result path, run, lane, task,
startup skill, and bundle digest must match the child claim. Native stores the observed result
bytes digest while holding the run lock. A reviewer result uses the canonical
`shepherd.review-result/1` document, binds the exact subject result and task digests, and cannot
be minted from a changed subject. `redo`, `red`, and `blocked` reviews require findings; an
explicit empty findings array is valid only for green/pass no-findings.

## Rejection custody

Count rejections per agent/task/generation. One through three permit bounded redo/re-review. Fourth records Native malignant/revoked/quarantined state, evidence digests and no-resume before root receives lineage-bound replacement custody. Never reset counts or hide retries.
