What is read, and when
Content an agent or a human explicitly hands to a Zephr tool call
On zephr_remember — never inferred from a transcript in the background
File paths, line ranges, and content digests for the anchors a claim cites
When a claim is anchored, and again when a cited file changes
Git metadata for the admitted worktree — commit SHAs, branch, worktree identity
On admission, and on every revalidation of the binding
The project boundary you approved, and nothing outside it
Established once by zephr project approve; immutable for the connection