## ADDED Requirements ### Requirement: Reviewed zero-alive backlog is held across source scopes The system SHALL apply the existing exact audited cold lifecycle to every approved source/platform/query scope in a reviewed zero-alive cohort. #### Scenario: Eligible rejected-query row is selected - **WHEN** an unfenced `pending` or `deferred` row has an exact source/platform/query absent from active policy and present in approved rejected evidence - **THEN** the reviewed manifest SHALL be permitted to transition the row to `cold` #### Scenario: Rejected cohort contains a fenced row - **WHEN** any selected row has an active queue, resolver, reservation, or Docker content lease - **THEN** apply SHALL fail closed without partially transitioning that manifest #### Scenario: Retired pair is rediscovered - **WHEN** ordinary enqueue or rediscovery encounters a cold target previously attributed to a rejected pair - **THEN** the target SHALL remain cold until an explicit reviewed reactivation ## MODIFIED Requirements ### Requirement: Stale-query selection follows canonical policy The system SHALL evaluate query staleness using case-sensitive exact source, platform, and query policy derived from canonical active and rejected configuration. #### Scenario: Configured query remains active - **WHEN** a queue row's exact source/platform/query triple remains configured in active policy - **THEN** automatic stale-policy planning SHALL NOT select the row #### Scenario: Attribution cannot be classified safely - **WHEN** query attribution is null, blank, operational, non-rotation, or belongs to an unknown source/platform pair - **THEN** automatic planning SHALL skip and report the row rather than inferring retirement #### Scenario: Rejected source cohort is planned - **WHEN** policy planning is scoped to an affected source/platform from the reviewed zero-alive cohort - **THEN** it SHALL include only eligible pending/deferred rows attributed to exact rejected queries and SHALL expose no target values #### Scenario: Rejected evidence and active policy disagree - **WHEN** rejected evidence does not match the canonical active-query omission or approved evidence identity - **THEN** planning and apply SHALL fail closed