Release
Release is the deliberate boundary between a reviewable local candidate and an external effect. An accepted package can remain local forever without being incomplete.
Review before effect
Source support, claim approval, voice and likeness authority, privacy and Portal use, accessibility, asset admission, and render validation each have an exact gate. Publication additionally pins the candidate digest, destination, audience, visibility, schedule, disclosures, cost, and approving Principal.
broadcast.publish_draft@1 and broadcast.publish_public@1 are separate effects. Each uses an
idempotency key, exact payload and request digests, destination identity, reconciliation lookup,
and PublicationReceipt@1. Lost acknowledgement leaves the outcome unknown until the platform
is inspected. Browser automation cannot become an untyped fallback, and no retry occurs merely to
obtain a cleaner receipt.
broadcast.correct_publication@1 publishes a forward correction. broadcast.takedown@1 requests
removal without erasing the earlier publication or receipt. A platform refusal, expired authority,
changed candidate, uncertain remote state, or failed gate ends with the exact blocker.
Restart requires pinned Pattern, source, handoff, script, timeline, renderer, adapter, and receipt revisions. Source snapshots, rejected renders, candidates, destination receipts, and analytics keep separate retention. Deletion inventories derivatives and requests authorized remote removal while preserving a content-free receipt; it cannot promise that caches or feeds forgot a published copy.
Proving package
Build a three-to-five-minute local package from a small frozen source set: source-linked claims, an
article and script, admitted local narration with back-transcript, admitted visual, music,
timed-language, and picture-sound bundles, captions, an explicit timeline, deterministic
render, one bounded repair, and final
EditorialPackage@1 plus PublicationCandidate@1. The proof makes no platform call.