Bodies Live by Digest
A large body does not sit inside a JSONL line. It is written once as a content-addressed artifact and named from the line by digest. The same rule covers raw vendor wire and compaction summaries. Each session directory has its own artifacts/ tree. Identical bytes get the same digest name, but they do not share one file across sessions. Changing a body without changing its digest is not an option the engine offers.
Secrets stay out of the record. A token, a key-file path, or a password that leaked into a line is a defect, not a feature of 'complete provenance.' The record is meant to be readable by a later self and by a reviewer. A readable secret is a published secret.
Owned Versus Observed
Some facts Firebrand wrote: the request it assembled, the tool it ran, the result it stored. Some facts it only saw: a vendor reason string, a stream that ended early, a child process exit. The record marks that difference. Treating observed wire as owned policy is how a dialect bug becomes 'the model decided.' Treating owned policy as observed weather is how a cap looks like an accident.