| Runtime | Unknown network, wrong chain, pool mismatch | Block reads, proving, and submission | Re-select bundled runtime; verify RPC chain |
| Recovery | Parse, checksum, context, or commitment mismatch | Do not count note | Preserve original bytes; locate matching runtime or backup |
| Membership | Missing leaf, invalid path, expired root | Do not prove | Refresh events and path from configured deployment |
| Spent state | RPC unavailable or nullifier already recorded | Do not mark available | Retry read; reconcile prior withdrawal |
| Artifacts | Missing pin, hash mismatch, oversize bytes, wrong verifier or order | Do not buffer further or prove | Restore trusted bundled configuration and exact artifacts |
| Witness | Amount, fee, payload, or context mismatch | Do not call prover | Rebuild intent from current state |
| Proof | Local verification fails | Do not preflight | Discard package; investigate witness and artifacts |
| Preflight | Revert, stale fee, spent nullifier, wrong chain | Do not submit | Resolve state drift; generate fresh proof when needed |
| Transport | Wallet or relayer result unknown | Do not switch path or nonce | Preserve identity; reconcile chain outcome |
| Settlement | Receipt lacks expected pool event | Do not mark the child spent or available | Inspect target, receipt, Withdrawal, and nullifier state |