# Build 2 — Boundary map and transfer evidence

Worked map (provided assistance, not your independent submission):

| Check | Boundary | Observation | What it does not establish |
| --- | --- | --- | --- |
| v10/v9 numeric order | Unit: pure function | Returned values/input ownership | Provider or filesystem behavior |
| FakeProvider exact id/status/order | Contract: declared provider shape | Typed schema, calls, failure propagation | A real service implements this contract |
| NEW snapshot read-back | Integration: collector + real file helper | Actual bytes/typed ordered JSON/hash/no overwrite | Cloud storage, races, privacy or rollback |

A fake is controlled input, not evidence about a real provider. A file existing
is not enough: read actual values and verify the actual-byte receipt. The tests
use invented records, no credentials and no external connections. Socket/DNS
refusals prevent accidental exercise network; they are not a hostile-code sandbox.

Your own evidence (fill this in; a blank table is not completion):

| Test name you authored | Unit / contract / integration and why | Changed input or failure | Actual observation | Still untested |
| --- | --- | --- | --- | --- |
| | | | | |
| | | | | |
| | | | | |

Add one test that would fail if request order changed, one malformed provider
response, and one actual NEW-file roundtrip. Explain why adding more mocks cannot
replace that actual file observation. State that reviewed `save_snapshot` and
schema helpers were supplied. If you change the supported schema, revise both
the declaration and tests; do not silently drop fields to make a fixture pass.

Transfer: supply IDs in a new order and use a fake returning `failed` for one job.
Does that provider status automatically mean low video quality? No: it is machine
metadata, not an authored creative finding. Demonstrate the exact output and
the test that protects the distinction. Keep files local and invented.
