{
  "schemaVersion": 1,
  "tenant": { "domain": "painkiller.care", "corporateDomain": "electrome.com" },
  "modules": [
    {
      "id": "crawlers",
      "artifacts": ["/robots.txt", "/.well-known/ai.txt"],
      "verify": ["GET /robots.txt -> 200, per-agent allow/deny block present", "GET /.well-known/ai.txt -> 200, allow/disallow/contact present"],
      "rollback": "Restore previous robots.txt from git; no DB writes."
    },
    {
      "id": "sitemaps",
      "artifacts": ["/sitemap.xml", "/sitemap-news.xml", "/feed.xml"],
      "verify": ["GET /sitemap.xml -> 200, XML well-formed", "GET /sitemap-news.xml -> 200, news schema valid", "GET /feed.xml -> 200, Atom 1.0 valid"],
      "rollback": "Restore static files from git."
    },
    {
      "id": "structured-data",
      "artifacts": ["JSON-LD blocks on every public route"],
      "verify": ["Rich Results Test green; required @type present"],
      "rollback": "Remove <SchemaOrg> components from page templates."
    },
    {
      "id": "llms-txt",
      "artifacts": ["/llms.txt", "/llms-full.txt"],
      "verify": ["GET /llms.txt -> 200, text/plain, H1 + sections present"],
      "rollback": "Restore previous static files from git."
    },
    {
      "id": "public-api",
      "artifacts": ["/openapi-public.json", "/api/public/catalog", "/api/public/faq", "/api/public/press", "/api/public/science", "/api/public/locator"],
      "verify": ["Spectral lint green; tags include catalog, faq, press, science, store-locator"],
      "rollback": "Unmount /api/public/* routers; spec stays static."
    },
    {
      "id": "agent-manifest",
      "artifacts": ["/.well-known/agent.json", "/.well-known/mcp.json", "/.well-known/ai-plugin.json"],
      "verify": ["GET each -> 200; A2A / MCP / plugin schemas valid"],
      "rollback": "Remove route handlers; no client breakage."
    },
    {
      "id": "agent-trust",
      "artifacts": ["/.well-known/did.json"],
      "verify": ["W3C DID 1.0 valid; placeholder key flagged"],
      "rollback": "Remove did.json route; downstream signing disabled."
    },
    {
      "id": "portal-noindex",
      "artifacts": ["X-Robots-Tag: noindex on /api/{admin,investor,retailer,affiliate,provider,provider-rx,patients,investor-docs,retailer-docs,retailers}"],
      "verify": ["HEAD each portal API -> response carries 'X-Robots-Tag: noindex'"],
      "rollback": "Remove portalNoIndexHeader from routes.ts mounts."
    },
    {
      "id": "internal-rag",
      "artifacts": ["Permission-filtered Growthie retrieval"],
      "verify": ["Cross-role red-team probe set returns no leakage"],
      "rollback": "Revert retrieval filter; falls back to public-only corpus.",
      "status": "planned"
    }
  ]
}
