One page each for machined, secrets, sessiond — what each owns, what
crosses its boundary, and the open gaps before it reaches the RedFlag
capability-token bar. Gaps mapped to concrete RedFlag primitives (token,
closure hash, canonical message, KeyID, independent verifier, binary
integrity, eBPF) with file:line anchors, not doctrine-summary hand-waving.
audit-status.md rolls up priority: P0 unlock/handoff attestation, P1
machined token issuance, P2 secrets caller identity, P3 per-agent UIDs,
P4 binary watchdog shared-deferred with RedFlag SEC-022.