Review, report and handoff
Readiness means the record is sufficiently complete for a stated purpose. It does not mean every stakeholder agrees, every relationship is true, participation was sufficient, or the system will behave as mapped.
Before authorization, review:
- critical and highly affected actors without direct or accountable representation;
- concentrated power, conflicts, dependencies and unverified relationships;
- missing evidence, stale assessments and uncertain possible matches kept as separate records;
- proxy, anonymous and sensitive records;
- participation promises without owner, dates, accessibility support, privacy safeguards or feedback loop;
- dissent, reservations, excluded perspectives and map limitations;
- whether the authorized reviewer has the right to approve this use of the map.
Record reviewer, decision, rationale, conditions, reservations, authorization date and next review. Authorization is bound to a fingerprint of the substantive context, provenance, domains, actors, assessments, voices, relationships, plans, safeguards and facilitator notes. It excludes workflow status and export packaging. A missing or mismatched fingerprint, a planning-ready/endorsed status inconsistent with the review decision, or a passed next-review date makes the authorization invalid for reuse or publication. Imported or AI-origin analytical records also need their own named reviewer and timestamp.
Public disclosure is a separate human decision. A named person must confirm a second fingerprint covering the exact final title, summary, target and audience, referentially resolved selection, every public narrative list, and the actor identity/label/sensitivity/consent inventory used for filtering. Any later change to that disclosure surface makes the confirmation stale and blocks public copy, report, PDF, and JSON export until reconfirmed.
Publishing freezes the active version as an immutable authorized snapshot. Reopening or unpublishing never edits that historical record: it creates a new active draft, preserves working content, and resets version-specific human review and public-disclosure authorization. Published Stakeholder versions cannot be edited, restored over, or deleted through version operations; deleting the entire model remains a separate deliberate administrative action.
Handoff contract
The internal or restricted structured package includes purpose and perspective, explicit selections, priority actors, highly affected or underrepresented groups, key relationships and dependencies, power concentrations, participation commitments, safeguards, evidence gaps, reservations, next actions, source provenance and version identifiers. It is referentially closed: selected safeguards bring their linked actors, relationships and plans; relationships bring both endpoints; plans bring their actor; selected actors bring their assessment and voice records, whose linked assessor or contributor actors are also included; domains bring ancestors; and used records bring their source artifacts.
Public handoffs deliberately do not expose that analytical graph. The projected model contains only selected, eligible public labels and the exactly confirmed narrative lists. Public reports may add aggregate readiness, authorization state, and critical/warning counts, without detailed findings. Ratings, assessments, voices, relationships, plans, safeguards, evidence, contact and access details, source lineage, internal model/version identifiers, and reviewer identity remain withheld.
The comprehensive web report and branded PDF communicate the same governed view. An internal PDF embeds the normalized internal record; a public PDF embeds the privacy-projected model plus its aggregate governance summary and displays a projection notice. Distribute internal reports according to their access classification. Neither format replaces consent records, statutory consultation, safeguarding review or regulated impact assessment.