Detection: the Assurance Office is an aggregate Observer master
Observer gains WatchedInput — Channels(signature kinds) for the human cast, Filings for aggregates — and the Assurance Office moves from a bespoke assurance: f32 scalar into Detection::observers as an aggregate Observer. It samples the field observers' policy-weighted filed suspicion on its own cadence (400 ticks, acuity 0.5, both [TUNE]) and accrues/decays through the exact same tick machinery as everyone else. The quarterly audit now checks the Office's own accumulated suspicion against the threshold, so sustained filed concern is what triggers containment rather than a snapshot average at audit time. Save format bumps to v5: OBS lines encode the watched input (channel chars, or "@" for filings) and v4's scalar DETECT assurance migrates into the Office observer on load. Frontends list the human cast via field_observers(); the Assurance band line is unchanged. Defense: DESIGN.md "Self-similar scale" (aggregate-observer law) states an aggregate observer's suspicion is the filed output of its sub-observers, computed by the same accumulate/decay it uses on raw signatures; the scalar Office violated it, and was recorded as the priority scale-debt in knowledge/architecture.md and as a known refactor in spec/detection.md. Save v5 with v4 migration satisfies the player contract's continuity clause. Audit semantics shift (accumulated Office suspicion vs snapshot average) is the law's stated computation; the constants stay within spec [TUNE] latitude.