Verified claim-by-claim against the engine/dispatcher/preinstall runner/manifests.
Corrections (3 were ship-blocking):
- Timeline (ship-blocking): identity files (pc-type/machine-number/cmm version/
site-config) are written in WinPE at the PXE menu BEFORE the image boots, not
during a post-imaging 'enrollment' step; preinstall already reads them. Added a
step [0]; enrollment is now only Intune + Azure DSC credential provisioning.
- _CmmVersion (ship-blocking): a CMM bay with NO resolved version gets ALL
PC-DMIS versions (legacy install-all), not none.
- machine-number 9999 (ship-blocking): the enforcement engine does not
special-case 9999; it is a placeholder that won't match real bay gates (the
9999-skip is status-write-back only).
- Preinstall runner implements only MSI/EXE + Registry/File detection, not the
full matrix (that is runtime-only).
- Runtime processes up to three scopes: common, type, then optional type-subtype.
- pc-subtype.txt is legacy (no longer written at imaging since 2026-05-04).
- The collector ComputerType mapping lives at Settings > Collector PC Types, not
the geenforce scope (scope computertypeid is a local reference field).
- FileVersion is a raw string compare; 4-part is convention, not engine-enforced.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>