# Governed Service To Decision This product package composes independently owned institutional semantics into one reconstructable administrative journey: ```text Service discovery -> Case intake -> Party and representation -> Mandate resolution -> approval/deliberation -> formal Decision -> observed delivery effect -> record and review references ``` An installed Forms and Forms Runtime pair adds an alternative governed entry path before case/workflow handoff: ```text Service discovery -> exact Form revision -> validated draft/submission -> receipt and handoff evidence -> Case or Workflow owner ``` Services, Cases, Parties, Mandates, Committee, and Decisions retain immutable provider-owned revisions for the parts they own. Portal, Cases, and Committee consume capabilities for cross-module semantics only. The package does not grant cross-module table access and can omit optional presentation, work, deliberation, delivery, or records modules while retaining explicit references to externally performed steps. ## Security And Recovery Every provider is tenant-bound. Missing or conflicting authority fails closed. Protected Decision content has a separate permission. Writes are replay-safe and OCC-guarded. Database restore is the semantic-state recovery unit; file and communication effects remain governed by their owning providers and are linked through requested/observed effect, evidence, and audit references. The executable fixture in `tests/test_institutional_governance_journey.py` proves SQL-backed Service, Case, Party, Mandate, Committee meeting/agendum/vote/minute, and Decision state. `tests/test_institutional_service_journey.py` separately proves exact Portal Form launch, persisted submission provenance, and idempotent replay. Target-environment accessibility, security, operator, privacy, delivery-provider, and recovery evidence are still required before this product package may claim `reference_ready` maturity.