{"packet":{"packetId":"lb2-evidence-intake-agent-rdp-cem-windows","generatedAt":"2026-09-11T20:49:36.393Z","status":"waiting_for_supervised_evidence","source":{"agentId":"agent-rdp-cem-windows","agentReadiness":"stale","agentMode":"simulator","stationHostname":"cem-win-lab-01","agentHeartbeatAgeSeconds":6701936,"staleThresholdSeconds":900,"latestObservationReportId":null,"latestUiMapReportId":"agent-ui-map-1782457840215-59","latestObservedScreen":"Liberty Blue 2.0 active window"},"acceptedSubmissions":[{"key":"observation","label":"Read-only observation report","endpoint":"/v1/cem/agent/observations","purpose":"Refresh Liberty Blue window, component, sensor, maintenance-attention, integration-surface, and disconnected-instrument evidence without opening a command channel.","requiredFields":["agentId, instrumentId, stationHostname, capturedAt, and mode=read_only_discovery.","libertyBlueWindowTitle, libertyBlueSoftwareVersion, and observedScreen.","components, sensors, maintenanceAttention, integrationSurfaces, and operatorNotes.","safetyFlags.instrumentDisconnected plus noHardwareChannel=true, noCommandChannel=true, noStateChangingActions=true."],"requiredSafetyFlags":["instrumentDisconnected must reflect the supervised local evidence.","noHardwareChannel=true","noCommandChannel=true","noStateChangingActions=true"],"forbiddenPayloadSignals":["No action log indicating PowerShell/RDP automation, UI clicking, typing, file copy, diagnostics, maintenance, setup edit, export, or START/PAUSE/STOP.","No command lease id, dry-run execution id, navigation package execution, or hardware/control channel reference."]},{"key":"ui_map","label":"Read-only UI map report","endpoint":"/v1/cem/agent/ui-map","purpose":"Refresh visible Liberty Blue screen labels, menu/tab structure, enabled states, and risk classification for screen parity without clicking controls.","requiredFields":["agentId, instrumentId, stationHostname, capturedAt, and mode=read_only_ui_map.","libertyBlueWindowTitle, libertyBlueSoftwareVersion, observedScreen, elements, blockedActions, and operatorNotes.","Each element includes label, controlType, automationId, path, enabled, visible, riskClass, allowedForDryRun, and notes.","safetyFlags.instrumentDisconnected plus noHardwareChannel=true, noCommandChannel=true, noStateChangingActions=true, noClicksPerformed=true."],"requiredSafetyFlags":["instrumentDisconnected must reflect the supervised local evidence.","noHardwareChannel=true","noCommandChannel=true","noStateChangingActions=true","noClicksPerformed=true"],"forbiddenPayloadSignals":["No element marked allowedForDryRun=true when its riskClass is controlled, high_impact, or unknown.","No evidence of clicking, focusing controls, accepting dialogs, changing screens, changing setup, exporting files, diagnostics, maintenance, or run-control."]}],"payloadExamples":{"observation":{"mode":"read_only_discovery","safetyFlags":{"instrumentDisconnected":true,"noHardwareChannel":true,"noCommandChannel":true,"noStateChangingActions":true},"operatorNotes":["Local operator supervised the read-only evidence capture.","No START/PAUSE/STOP, setup, diagnostic, maintenance, export, command, or hardware action was attempted."]},"uiMap":{"mode":"read_only_ui_map","safetyFlags":{"instrumentDisconnected":true,"noHardwareChannel":true,"noCommandChannel":true,"noStateChangingActions":true,"noClicksPerformed":true},"operatorNotes":["Local operator supervised the read-only evidence capture.","No START/PAUSE/STOP, setup, diagnostic, maintenance, export, command, or hardware action was attempted."]}},"approvalSummary":{"stationActionApprovedCount":0,"libertyBlueWriteApprovedCount":0,"inventoryWriteApprovedCount":0,"diagnosticsExecutionApprovedCount":0,"reportExportApprovedCount":0,"runControlApprovedCount":0,"navigationRequestCreatedCount":0,"navigationPackageCreatedCount":0},"operatorChecklist":["Confirm a local operator is supervising the Liberty Blue 2.0 station before accepting a payload.","Confirm the payload is an observation or UI map only and uses the accepted endpoint shown in this packet.","Confirm all required safety flags are present and true except instrumentDisconnected, which must match local evidence.","Confirm the operator note states no START/PAUSE/STOP, setup, diagnostics, maintenance, export, command, or hardware action was attempted.","After intake, review Screen Parity and only then prepare at most one request-only navigation pilot."],"acceptedEvidenceAfterSubmit":["Fresh observation report id or UI map report id.","Observed Liberty Blue screen title and visible labels.","Safety flags proving no hardware channel, no command channel, and no state-changing actions.","Operator note confirming local supervision and no final-stage run-control action."],"forbiddenActions":["Do not start the Windows Agent from this packet.","Do not open RDP, run PowerShell, click Liberty Blue, type keys, change screens, save methods, change reagents or bottle setup, run diagnostics, run maintenance, export files, START/PAUSE/STOP synthesis, or affect hardware.","Do not create navigation requests or packages from stale or incomplete evidence."],"operatorSummary":"Read-only Evidence Intake Packet converts the recovery gate into an operator submission checklist for fresh observation/UI-map evidence; it is not an execution approval and does not create navigation work.","nextAction":"Accept only a fresh supervised read-only observation or UI map payload; do not create navigation packages from stale evidence.","safetyBoundary":["Read-only Evidence Intake Packet is an API/UI contract for supervised evidence payloads only.","Fetching this packet does not connect to Windows, start the Windows Agent, open RDP, click Liberty Blue, submit evidence, create navigation requests, create packages, execute diagnostics, execute maintenance, export files, start/pause/stop synthesis, or affect hardware.","Any real evidence capture must be separately supervised locally and submitted by an approved agent path with the required safety flags.","Web STOP is not a physical emergency stop and this packet does not approve run-control."]}}