Say what a persona protocol opens and what it closes. master
PERSONAS rendered the archetype registry at the player: "legal actions: message, request, deceive, review" is PersonaActionKind verbatim, "grant route:" is PersonaGrantKind, and counterparty rows were an integrity=/recognized=/regard= field dump. Each identity and creation row now leads with the standing institutional reading, then one can: line and one cannot: line drawn from the same fixed act list in the same order, so two protocols compare directly. Standing, grants, expectations, contradictions, and correlations read as sentences naming the observer who holds them. Review is declared by the Research and Security protocols and consumed by no world system, so it is filtered out of both reach lines under the standing stub rule rather than advertising capability those archetypes cannot exercise. The visible consequence is deliberate: Security now shows a strictly smaller reach than Research, because that is what the build is. Defense: operations-workspace.md's copy law forbids raw enum names in human fields and criterion 22 requires world terms; this surface was breaking both, and the fix stays inside the one renderer-neutral projection so terminal, Bevy, and agent mode inherit it with no frontend-only path. Every exact id remains on OperationsTarget, ActionCommand, and agent rows, so human_operations_copy_omits_internal_bindings_but_agent_targets_keep_them passes unchanged. Hiding an unconsumed verb applies action-vocabulary.md's existing rule that STUB entries stay off every player surface until playable. persona_copy_names_world_acts_and_omits_unhonored_protocol_verbs pins the paired reach lines, the absent Review verb, and the removal of the four dump prefixes; the per-counterparty integrity Defense gains a clause requiring every standing phrase to name whose read it is, so it cannot go vacuous now that the word integrity is gone from human copy. No legality, grant, lifecycle, or evidence behavior changes.