## Recovery and safe disclosure checklists

These are reader checklists\,&#32;not automatic session tests\.&#32;Checking a box records your own work\;&#32;it does not mean a website inspected OMP\,&#32;your files\,&#32;or a provider\.

### Recovery checklist

When selection or transition behavior is uncertain\:

- \[&#32;\]&#32;**Stop adding work\.**&#32;Do not prompt the possibly wrong conversation\.
- \[&#32;\]&#32;**Identify the operation\.**&#32;Resume\,&#32;continue\,&#32;fork\,&#32;fresh\,&#32;clear\,&#32;and new have different expected effects\.
- \[&#32;\]&#32;**Check the active session file\.**&#32;Do not rely on title or a success toast\.
- \[&#32;\]&#32;**Check persistent identity separately from provider identity\.**&#32;Use the saved session header for durable identity\.
- \[&#32;\]&#32;**Check directories\.**&#32;Inspect the active working directory and additional roots\;&#32;distinguish them from an old header cwd\.
- \[&#32;\]&#32;**Account for queues and jobs\.**&#32;Fresh\/fork can retain ordinary queues\;&#32;clear\/new discard them\.&#32;Cancellation does not reverse completed file effects\.
- \[&#32;\]&#32;**Inspect the relevant journal\.**&#32;A reset boundary explains why old entries remain while current context is empty\.
- \[&#32;\]&#32;**Treat failure phase as evidence\.**&#32;A settings preflight failure\,&#32;hook veto\,&#32;guarded rollback\,&#32;and post\-commit reconciliation error are different outcomes\.
- \[&#32;\]&#32;**Use an explicit known target for recovery\.**&#32;Do not repeatedly try continue and hope recency chooses correctly\.
- \[&#32;\]&#32;**Preserve useful evidence privately\.**&#32;Do not clear or drop merely to make the screen look simpler\.

If a persistence error leaves live messages ahead of disk\,&#32;do not assume restart will recover those messages\.&#32;If you need a diagnostic copy\,&#32;treat any dump and sidecar as sensitive and review them locally\.&#32;Do not publish a raw dump as a shortcut\.

If cwd re\-scoping fails\,&#32;do not let tools operate while scope is uncertain\.&#32;The parent terminal shell’s directory alone does not prove the OMP process and manager agree\.

### Safe disclosure checklist

Before forwarding any real packet outside its current trusted boundary\:

- \[&#32;\]&#32;**Name the recipient and purpose\.**&#32;Include only what that review requires\.
- \[&#32;\]&#32;**Identify the snapshot source\.**&#32;Live dump\,&#32;file export\,&#32;live export\,&#32;default share\,&#32;or custom HTML are not interchangeable\.
- \[&#32;\]&#32;**Inspect older history\.**&#32;Include pre\-clear entries and alternative branches in the review scope\.
- \[&#32;\]&#32;**Inspect all nested content actually embedded\.**&#32;Do not stop at the parent’s task summary\.
- \[&#32;\]&#32;**Inspect header and metadata paths\.**&#32;Cwd\,&#32;additional roots\,&#32;titles\,&#32;parent references\,&#32;and other identifiers can disclose project or user information\.
- \[&#32;\]&#32;**Inspect system\/tool data without republishing it blindly\.**&#32;Current prompts\,&#32;tool descriptions\,&#32;schemas\,&#32;file mentions\,&#32;and opaque metadata require deliberate handling\.
- \[&#32;\]&#32;**Inspect images and linked content\.**&#32;Text redaction does not inspect every pixel or authorize loading every external resource\.
- \[&#32;\]&#32;**Separate visibility from removal\.**&#32;Filters\,&#32;collapsed sections\,&#32;and blank viewers do not scrub embedded bytes\.
- \[&#32;\]&#32;**Inventory sidecars and clipboard copies\.**&#32;They may outlive the command and the session\.
- \[&#32;\]&#32;**Check effective sharing configuration and custom\-handler presence\.**&#32;Review fallback destinations as well as the preferred destination\.
- \[&#32;\]&#32;**Treat redaction as assistance\,&#32;not approval\.**&#32;Unknown strings can survive\;&#32;no obfuscator can mean no typed redaction pass\.
- \[&#32;\]&#32;**Account for truncation\.**&#32;A smaller packet may omit crucial evidence without removing sensitive surviving content\.
- \[&#32;\]&#32;**Protect complete share links\.**&#32;The fragment key is access\-bearing\.
- \[&#32;\]&#32;**Do not interpret cancellation as revocation\.**&#32;A started operation may finish after the UI returns\.
- \[&#32;\]&#32;**Hold the packet if inspection is incomplete\.**&#32;An authorized\,&#32;manually written summary may be safer than forwarding an unreviewed full artifact\.

No live sharing is part of completing this workbook\.

### Finish the three desks

You have reached the intended outcome when you can explain these decisions without relying on a status label\:

| Situation | Sound conclusion |
| --- | --- |
| Maya knows yesterday’s full identity\. | Resume that known target and check file plus project scope\. |
| Continue returns an empty conversation\. | Investigate breadcrumb\/fresh\-boundary\/history availability\;&#32;do not assume deletion\. |
| Eli wants a second conversational direction\. | Fork\,&#32;while recognizing that workspace files remain shared\. |
| Eli wants to retain the conversation but reset local provider state\. | Fresh\;&#32;do not claim a remote incident was repaired\. |
| Eli wants an empty live conversation under the same persistent ID\. | Clear\;&#32;retained journal history still needs export review\. |
| Noor needs the earlier Harbor Notes discussion\. | Inspect saved\/full history\,&#32;not only post\-clear live messages\. |
| Noor’s blocked\-CDN HTML shows only controls\. | Use raw or decoded data inspection\;&#32;the viewer is not self\-contained offline\. |
| A sharing loader says cancelled\. | Treat upload\/handler completion as unresolved\,&#32;not revoked\. |

### Clean up only owned exercise material

`LAB`&#32;identifies the newly created temporary lab\.&#32;`RECEIPT`&#32;identifies a separate temporary JSON receipt\.

When finished\,&#32;remove only the exact exercise paths you own and no longer need\.&#32;The generated Review Packet HTML belongs to your disposable downloaded examples copy\.

No automated cleanup command is supplied that could be mistaken for a real\-session deletion instruction\.&#32;Do not use&#32;`/drop`&#32;as workbook cleanup\,&#32;and do not describe ordinary file removal as secure erasure\.
