personal memory agent

feat(think): synthesis access-tier — sol-surface-only cogitate (no raw-fs reads) master

Add a fourth locked cogitate access tier `synthesis` (sol=True, reads=False, submit=False): the journal is reached only through `sol` domain commands, with no raw-filesystem read tier (read_file / list_directory / glob / grep_search) and no outbound submit. It fills the last meaningful corner of the (reads, submit) capability space — `outbound` was the only reads=False tier but it drags submit=True along, which is wrong for a pure synthesis talent. This is the mechanism half of the weekly_reflection fs-fallback fix; 23d6498a shipped the prose ("gather only through sol; do not walk the raw tree"), and a 2026-06-17 weekly run still logged 12 fs-fallback + 4 repeat-flail of 29 actions because the read tools were merely discouraged, not withheld. The tier removes them at registration, so the constraint the prose asks for is now enforced. Set weekly_reflection + partner to `synthesis`. weekly_reflection needed no body change (prose already forbids raw reads). partner had a live Step-1 `read_file identity/partner.md` dependency, swapped to `journal identity partner` (the settled sol-surface read form, policy-allowed at reads=False). The locked-contract RuntimeError guards keep COGITATE_ACCESS_TIERS in sync with the capability map; all caps/display/validation consumers are contract-driven and auto-adapt (openhands tool registration, cogitate_policy, talent_cli inventory + tier audit). Updated the contract vocabulary-lock test, added the capability row, made the finalization-harness tool-surface assertion tier-aware (weekly_reflection is now sol-only), and documented the tier in docs/COGITATE.md.