Attestations
Attest is a small typed value the phase-0 policy emits and the phase-1/2
policy reads. v1 defines it as H(ATTEST, kind, salt, payload...) with a
kind registry in protocol/schema/attestations-v1.json
(0 = none, 1 = screened(originator_hash), 2 = approved(officer_id)).
The preimage travels in the envelope (§4.11), so a recipient rule can
require ctx.attestation_in().is(Screened). Both FIs must agree on kinds;
the schema file is the agreement.