Verified staff/service with ledger:repo:read reads the retained immutable source and digest, current observation date separately from requested close coverage, actual journals, debt, full-lot collateral and explicit unresolved readiness blockers. Bridge authority alone cannot read bank-wide source snapshots. Missing or unknown evidence cannot be silently replaced by projected cash, zero default cost or released collateral. Every route requires verified non-API-key authority even locally; customer actors are refused. JSON evidence is one strict object bounded at 5 MiB. Complete responses are bounded at 16 MiB and fail explicitly without truncation.