Embedded Semantics integration-kit instructions v1

Selected recipe: Agent and workflow routing (workflow-routing)
Best placement: Immediately before a semantic routing decision whose policy already recognizes published codes.

Purpose
Use the first-party HTTPS resolver only when this workflow needs a stable governed ConceptCode at the selected durable boundary.

Required decision rule
1. Preserve originalExpression, language or null, semanticOutcome, and complete resolverEvidence for every outcome.
2. Add conceptCode and registryVersion only when data.status is "resolved" and both returned strings are non-empty.
3. Unknown, ambiguous, malformed, request failure, and service error mean no ConceptCode assignment.
4. Never construct, translate, approximate, repair, or guess a ConceptCode locally.
5. Evaluate authorization under a separate policy and record its version before any side effect.
6. A ConceptCode and a passing local conformance report never authorize an action.

Safe sequence
- Run the local fixture mode first. It makes zero network calls and performs zero side effects.
- Inspect local-conformance-report.json and integration-manifest.json.
- Review the generated adapter source before enabling live mode.
- Use live mode only through an explicit operator action against https://embeddedsemantics.com.
- Preserve any live response as evidence, but keep it outside the deterministic kit integrity proof.

What the kit proves
The checked source and fixtures demonstrate fail-closed client interpretation for six fixed outcomes and resolved-only identity assignment.

What the kit does not prove
It does not prove live deployment, arbitrary-expression coverage, network retry behavior in every host, downstream permission, model quality, or semantic generalization.
