BLOCKED + UNKNOWN_WRITE_STATE + PENDING
Separate reading, proposing, approving, executing, verifying and recovering into auditable permissions and states.
GOVERNANCE / LOCALIZED DECISION BRIEF
Reading, proposing, approving, executing and verifying are distinct permissions. Every gate binds a role, scope, version and validity period.
REFERENCE_ARCHITECTURE · REFERENCE_SUPPORT

The AI control layer forms a decision; one human approval gate confirms role, scope and version; the approved action enters the system; formal state is read back as evidence.
Forms a proposal from traceable sources without writing directly to a system.
A named approval binds role, scope, version and validity.
Only the approved version enters a target system through least privilege.
Independent verification reads formal state back into an auditable loop.
REFERENCE ARCHITECTURE · SYNTHETIC ILLUSTRATION · NO PRODUCTION CONNECTION, CUSTOMER DEPLOYMENT OR IMPACT CLAIM

The reviewer sees the proposal, allowed actions, blocked actions and supporting evidence together.
SYNTHETIC PRODUCT UI · REFERENCE ARCHITECTURE · NO CUSTOMER DATA · NO PRODUCTION CONNECTIONPAGE ROUTE / governance
Separate reading, proposing, approving, executing, verifying and recovering into auditable permissions and states.
Separate reading, proposing, approving, executing, verifying and recovering into auditable permissions and states.
Separate reading, proposing, approving, executing, verifying and recovering into auditable permissions and states.
KNOWLEDGE → COMPARISON → DIRECTION → OPTIMIZATION
The full-detail canonical evidence record remains available in Chinese. IDs, Truth classes, boundaries, and source references stay unchanged across languages.
Source-traceable reference
Compare the same operating fields before choosing a direction.
Confirm the owner, authority, human gate, and readback rule.
Define a baseline, target, owner, and observation window before claiming impact.