Use identical labels where the dependency is truly shared.
Design for recovery.
Three files can all be valid and still fail together. Change the declared dependencies below to see what remains when one site, infrastructure system, or custodian becomes unavailable.
A different filename on the same system is still one infrastructure domain.
Any two distinct healthy shares reconstruct the handoff.
All single-domain losses leave two shares
Failure rehearsal
Select a failure to see its impact on all three shares. Each row removes every share with the same declared label. A recovery path needs at least two survivors.
Take the plan to the actual copies
Import or download a placement manifest locally, then run the JavaScript or independent Python assessment against three retrieved share files and your separately held trusted policy. The lab alone cannot mark storage ready.
The full assessment recomputes the three-pair drill under an external accepted head and tests recovery after each declared loss. Keep the trust policy outside the shares. A passing result remains a project-authored local check, not independent custody proof.