# Portfolio I — Asset Intelligence CLI defense

Copy this document before filling it in. Do not paste real credentials, private
media paths or customer records. A worked reference run is not your implementation.

## 1. Contract and operator

Who will use your tool? What inputs, outputs and declared rules does it support?
Explain why a filename/sidecar report cannot certify actual media contents.

## 2. Your implementation and setup

Record your Python version, environment setup and exact practice test command.
Which three functions and CLI did you implement? Identify reviewed helpers you
reused. Record assistance used; do not relabel guided work as independent.

## 3. Evidence from changed data

Record a changed fixture dry run and its status. Show metadata failures alongside
accepted assets, global proposed names, units and class counts. Reconcile total
inventory to accepted plus failed. Explain why the status is 0, 1 or 2.

## 4. Export and refusal evidence

Show the two matching typed inventories, final report and parseable audit log
from a new output folder. Repeat the command at the same destination and show
the refusal without changed files. Explain the partial-output failure policy.

## 5. Test defense and independent change

Choose one normal, one boundary and one failure test. Explain what each proves
and what it does not. Add a new test before changing code. For example: enforce
an additional documented review rule or retain an extra non-secret provenance
field. Explain the required schema, CLI, test and README changes; do not silently
change the existing policy just to pass the reference checks.

## 6. Limitations, assistance and handoff

List at least three limits: fixture metadata rather than decoding, non-atomic
exports, bounded key redaction rather than universal secret detection, or owned
directories rather than a hostile-filesystem sandbox. Explain what remains
before real production use. Have another person reproduce setup and one run;
record their actual outcome and stall points rather than inventing a user test.

## Self-review rubric (not automated certification)

- Contract: operator can tell what the tool does and does not do.
- Reproducibility: another person can run your files and changed fixtures.
- Correctness: checks pass against practice, not just reference; refusals remain visible.
- Evidence: types/counts/paths reconcile; credentials/raw exception text stay out of audit.
- Transfer: new requirement/test is explained independently, with assistance recorded.
- Honesty: known limitations, failed runs and self-reported local evidence are labeled.

A missing artifact or unexplained result needs revision. A green test suite or
quiz score alone does not award an independent portfolio pass.
