## Why The remaining discovery rotations still contain source/query pairs that have each completed at least 1,000 successful scans without ever producing an `alive` credential. Their retained pending and deferred work consumes most of the avoidable backlog even though the existing audited `cold` lifecycle can preserve it reversibly. ## What Changes - Retire only exact source/query pairs with at least 1,000 successful scans, zero historically `alive` linked credentials, and zero pending candidate checks at the evidence cutoff. - Keep a durable rejected-query registry with the source, exact query, evidence counters, cutoff, and reason `rejected_zero_alive` while removing each pair from active rotation. - Preserve dedicated source sentinel queries and evaluate the same query independently in different sources. - Move every eligible unfenced pending or deferred target attributed to the rejected pairs into the existing audited, reversible `cold` state instead of deleting queue or history rows. - Fail closed if attribution, evidence, policy identity, queue selection, or runtime quiescence changes between review and apply. ## Capabilities ### New Capabilities None. ### Modified Capabilities - `discovery-keyword-pruning`: Add source/query-specific retirement based on substantial zero-`alive` evidence and retain explicit rejected-query evidence. - `target-queue-policy-holds`: Apply the existing audited cold lifecycle to every reviewed source scope in the retired cohort. ## Impact The change affects `app/config.yaml`, query-policy validation and tests, private reviewed cold manifests, and `target_queue` policy events. The approved cohort contains 38 source/query pairs and 75,551 currently eligible queue rows. No target, scan, finding, credential, result, reservation, deduplication, or coverage record is deleted.