adapters/docstore/rclone.md fills the docstore slot with no desktop sync agent in the
path (Drive, OneDrive, Dropbox, S3, Box), and docs/drive-mount.md is the detect-and-guide
page for teams that do want the mount. Three safety properties came with it: a re-pointed
personal remote can no longer redirect a delivery past resolution_fingerprint, an adapter
can no longer declare its own destination key as personal, and source_material_guard
follows the backup verb to its new transport — tokenized, so shell quoting is no longer a
one-character bypass, for cp and rsync as well as rclone. Selftest 975 → 984, 0 failed.
All 22 tests/emit fixtures regenerated: the provenance header every emitted artifact
carries embeds the version, so a bump without regeneration turns byte-diff sections red
on main (the lesson of bc64b46).
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>