diff --git a/docs/PESETUP-INTERNALS.md b/docs/PESETUP-INTERNALS.md
index 161304d..7d3fbd8 100644
--- a/docs/PESETUP-INTERNALS.md
+++ b/docs/PESETUP-INTERNALS.md
@@ -7,6 +7,15 @@ tool turned out to be wrong and cost weeks of debugging.
**Version documented:** 4.0.0.17 (`Sources/PESetup.exe`, PE32+ native apphost
wrapping a .NET 6 single-file bundle, 468 embedded files).
+**Version in production:** 4.0.0.20, as of 2026-08-06 — the media reports it in
+its own log (`AppVersion: 4.0.0.20`). Everything in this document was verified
+against a 4.0.0.20 run on bay 579C144 that day: the media drive resolved to `Z:\`,
+`W:` was created by `PrepareDisk` and used for every copy destination, the fallback
+unattend at `Deploy\FlatUnattendW10.xml` was the one loaded, and driver selection
+matched `win11_optiplexd13mlk7020_a09.zip` by model. The decompiled detail below has
+not been re-derived from the 4.0.0.20 binary, so treat exact line-level claims as
+4.0.0.17 and the observed behaviour as current.
+
## How to re-derive this
The managed code is not directly readable - the outer PE has no managed
diff --git a/playbook/FlatUnattendW10-shopfloor.xml b/playbook/FlatUnattendW10-shopfloor.xml
index f1a96ca..0445f1d 100644
--- a/playbook/FlatUnattendW10-shopfloor.xml
+++ b/playbook/FlatUnattendW10-shopfloor.xml
@@ -136,7 +136,7 @@
true
SupportUser
- 7
+ 12