The role policy was unit-tested against the script the code generates. This probes the script the SERVER INSTALLED, inside a live mission container: the verifier's Write exits 2 with its reason, the lead's identical Write exits 0, the verifier's Read and another role's Edit exit 0, and the denial the deployed gate wrote names role-verifier-readonly and agent_type verifier. 5/5 on prod. Three of the four probes are negative controls. A gate that refused everything would pass the first and be worthless — the same trade the module's header refuses. 'Compiled in and CI-green' and 'enforced by the artifact in production' are different claims; the gap between them is this module's history. The record is matched with a shell glob on the raw JSON line, not a nested python -c: the first version could not survive quoting through bash, ssh and sh, and reported an empty record while the gate had written a correct one. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WZb5A2kfVfjpdwSochkuHz