Before Group 1 can pass, record the immutable pre-provisioning snapshot identifier, snapshot platform, creation UTC, VM identity, and an operator-tested restore command/result. Capture the absence of NEXXVU accounts, groups, units and paths; host/OS/kernel/architecture/Python/systemd identity; filesystem capacity; installed unit state; and package inventory hash. Store evidence outside the VM as well as in a root-only transaction directory. Every later group must preserve this record. Failure means stop; do not perform ad-hoc recursive cleanup. Restore the named snapshot only under a separate Hani #1 rollback authorization, then repeat the original absence checks.
