Contract changes require:
- a documented semantic reason;
- a schema update;
- at least one valid fixture;
- an invalid or boundary fixture that would catch a plausible defect;
- conformance tests;
- migration notes for wire-incompatible changes.
No attribute may be added without identifying the signal that carries it and how an instrumentor obtains it at runtime. New content-bearing fields require security and privacy review.