# Originality and claim-boundary review

## Editorial identity

- **Title:** *Facility Content Is Evidence, Not Command Authority: The Semantic Firewall for Self-Storage AI*
- **Thesis:** Emails, work orders, PDFs, images, webpages and tool output may supply bounded evidence to an AI workflow, but a separately enforced semantic-role boundary must prevent any such content from redefining the task, policy, tool catalog, permissions or operating outcome.
- **Proposed slug:** `facility-content-evidence-not-command-authority-semantic-firewall`
- **Practical tool:** `untrusted-content-boundary-matrix.csv`, a 32-field content-role, disposition, derivation, authority and readback record containing three entirely fictional examples and one blank implementation row.
- **Fictional example:** Silver Birch Storage and every related facility, file, email, webpage, source, asset, vendor, customer, event, record and outcome are invented for architecture testing.

## Current editorial and publication preflight

- The current governed editorial calendar contains 38 unique units. The older 28-row planning calendar was also screened. No row uses the selected title, slug, Silver Birch example or 32-field tool.
- The exact `2026-08-29/evening-ai-architecture` slot did not exist before this run. The automation memory ended with the completed 2026-08-28 evening package. The slot was open.
- The current-day morning lane is *When the Gate Won’t Open: A Safe Access-Incident Playbook for Self-Storage Managers*, a physical access-incident response method and 11-stage checklist. No 2026-08-29 midday package or memory entry existed at the final preflight; the most recent systems-lane article is the 2026-08-28 *Daily Portfolio Close*, a portfolio reconciliation method. Neither shares this article's semantic-role firewall, fictional example or tool.
- The prior evening article, *No Model Gets a Master Key*, governs the later seam where an already formed AI proposal requests authority to execute. The current article governs the earlier seam where external content enters model context and must remain evidence rather than instruction.
- The live Jared sitemap returned HTTP 200 with 53 canonical entries and SHA-256 `9ab9959bd17e48de8103f430b6674696c64baf7115464a11aad011021292f1fb` on 2026-08-29. The live modSTORAGE post sitemap returned HTTP 200 with 250 `loc` entries—125 post canonicals plus 125 image locations—and SHA-256 `f43b72d852f431d51a43ffaed8f59082bef531742752455d52c475e74cb93452`.
- Neither live sitemap contains the selected title, proposed slug, Silver Birch name or tool name. Exact web searches for the selected title and `semantic firewall` with self-storage returned no owned collision.

## Closest published and active work screened

- *The Operational Memory Contract* governs whether retrieved assertions have the correct identity, authority, effective time, entitlement and consequence. It includes quarantine as one source disposition. This article addresses a different failure: external content that attempts to act as an instruction and alter the workflow reading it.
- *The Semantic Safety Layer: Why AI-Ready Buildings Need an Operational Ontology* is an ASHB podcast guest concept sent once with sender-side verification only. It concerns entity and record meaning across building systems, not prompt injection, untrusted-content roles, hidden document layers or the evidence-versus-instruction boundary.
- *The Correction Propagation Contract* is already published and was rejected as a topic candidate before drafting this package. It governs downstream recomputation, retraction and replay after a source assertion changes.
- *The Event Bus Is Not the Source of Truth* was sent once to Inside Self-Storage; sender and attachment readback are verified while editorial handling and publication remain unconfirmed. It concerns event transport versus governing records.
- *From Dashboard Ranking to Defensible Facility Comparison* is the active IFMA FMJ comparison-contract manuscript. It concerns metric comparability across facilities, not content-to-instruction separation.
- *Retrieval Is Not Authority* was sent to Facilities Management Advisor; sender state is verified while delivery and editorial handling remain unconfirmed. It governs which retrieved assertions may support an answer or review packet.
- *A One-Property Technology Change Can Have a Portfolio-Wide Blast Radius* has a prepared Commercial Property Executive route that remains unsent. It maps pre-release change consumers and consequences.
- No title, thesis, slug, Silver Birch scenario or practical-tool collision was found across these works.

## Quantified local originality screen

- Screened 291 other Markdown files under the editorial execution workspace, excluding the new package and dependency, vendor and Git directories.
- Exact normalized body-sentence matches of 14 or more words: **0**.
- Unique six-word article-body shingles: **2,248**.
- Highest six-word-shingle overlap: **0.089%** (2 of 2,248), against *The Temporal Authority Envelope*.
- This is a bounded local-corpus collision screen, not a universal plagiarism determination. Source concepts are attributed and no external prose was intentionally copied.

## Claim boundaries

- No customer, deployment, partnership, integration, certification, product availability, performance, revenue, occupancy effect, adoption, award or recognition is asserted.
- Silver Birch Storage and all related records are labeled fictional before operational details appear. The matrix repeats the fictional and non-evidentiary boundary on each example row.
- Prompt injection is described as a risk class supported by current sources. The article makes no prevalence claim and does not claim that a real attempt occurred, that a real control blocked one or that any architecture eliminates the risk.
- A content hash, renderer, detector, quarantine state, provenance record, model output, human review, tool response and source-system readback are treated as different evidence states.
- Model output is never represented as observed facility fact. Facility content may inform an extraction but cannot grant itself instruction or action authority.
- OWASP pages are bounded as community security guidance, not standards or certification. NIST sources are bounded to cross-sector guidance and a flexible federal control catalog. OpenAI research is bounded to the paper's vendor-specific models, training and evaluation conditions. W3C PROV-O is bounded to provenance vocabulary.
- Jared's roles appear exactly as verified: Chief Operating Officer of modSTORAGE; CEO and Founder of Facily.ai. No tenure claim was needed.
- Governed image 060 is labeled AI-generated editorial material, not documentary evidence. The rejected black-turtleneck portrait was not used and no author portrait was needed.

## Truthful state

Complete, publication-ready local draft package. No publisher handoff, submission, publication, canonical URL, search submission, crawling, indexing, third-party coverage, award or recognition was created or observed in this run.
