- flat per-type deployed namespace enforced across own items and all sources
- own-vs-vendored and vendored-vs-vendored collisions abort with both parties named
- --rename upstream=deployed resolves collisions; on-disk folder always equals
deployed name; rename targets are validated against new collisions
- checks run before any tree mutation; validate re-checks the namespace offline
- validate: offline hard rules (all+include, exclude-without-all, orphaned
include entries vs pinned inventory) and lockfile/external-area divergence
- vendor list: name/url/ref/rev/mode/item counts, human + json
- vendor inspect: per-type inventory with frontmatter metadata and recorded
warnings read from the external area, human + json
- exit code 1 on invalid state for headless drift checks