# Archangel a6 physical acceptance checklist

This is a test plan, not a record of completed physical tests. Use harmless context and the same a6 wheel hash on both rigs.

1. Preserve a5 and a complete profile backup. Quit a5. Start a6 on the actual Mac/Linux/Windows targets. Record OS, architecture, Python minor, Ollama version and model digests. Confirm the Mac fixed runtime discovery and a new pre-a6 desktop/trust snapshot on an a5 profile.
2. Confirm identities and old messages are unchanged. Save/approve a6 rig cards both ways. Make a channel once, export/import its signed channel card. Two separately created identical names must remain isolated.
3. Start with all imported channel permissions off. A signed frame from an unapproved channel publisher must fail before commit. Enable only the intended publisher and use-in-chat independently.
4. Write/review/send one note Mac -> Linux. Inspect local and remote receipts. Query through channel Chat, expand the exact note evidence, verify the count, model digest and generation branch. Reverse the direction. Repeat Windows routes separately.
5. New chat with shared notes OFF must have zero shared context and exclude earlier answers grounded in notes. Revoke a publisher and repeat in an existing thread; history must reset. Notes from another channel must never appear.
6. Send the 73/75 conflicting threshold example as separate notes. Both alternatives must survive; answer receipt should show the conflict and supplied evidence. A guarded fallback must be visibly identified. No silent supersession.
7. Restart and verify channel definitions, permissions, sources, conversations and per-recipient locks persist. A forced stop during sending must leave attention/unconfirmed state, never an automatic replay. Do not force-stop sensitive real work.
8. Test phrase suggestions: relevant new user text creates only a draft; unrelated conversation does not. Automatic mode additionally requires an explicit channel authorization AND chat checkbox AND /note prefix. Ordinary model output, received notes and topic matches must not send. Verify hourly/five-second limits and immediate pause of new dispatches.
9. Export a reviewed signed note and import on the other a6 machine with the proper channel policy. Duplicate direct/file/QR delivery must not create a second accepted channel note under the same publisher/note ID. Physically render/scan QR chunks with the actual camera/display; software reassembly tests do not prove optical reliability.
10. Inspect partial multi-recipient outcomes, revoke a destination mid-work and verify no added recipients or blind retries. Reimport old channel/rig files only through explicit approvals; do not weaken certificate/route checks to get a test green.
11. Test an actually configured private overlay and network-address change separately. Managed Relay is not provisioned by this build and is not inferred from LAN/overlay success.
12. Quit cooperatively and relaunch twice. Check native Windows ACL/lock behavior, actual Mac quarantine/start path, and a cold target-matched offline pack. Confirm the loopback browser UI was not exposed publicly.

Only after this evidence is collected should the public website's download change from the demonstrated a5 build. An a6 UI screenshot or fixture model result is not substitute evidence.
