# Deployment evidence contract A UAT run binds to one immutable deployment tuple: ```text application_commit image_digests GitOps_commit ArgoCD_application ArgoCD_sync_revision cluster_environment base_url ``` Before execution, assert that the Argo CD application is synchronized to the declared GitOps commit and healthy. Where the environment exposes a version endpoint, compare its source/image identity with the handoff. Reject the handoff when: - an image tag is mutable and no digest is supplied; - Argo CD reports `OutOfSync`, `Unknown`, `Degraded`, or another non-healthy state; - the deployed source cannot be correlated to the handoff; - the base URL resolves to a different environment; - a newer synchronization occurs after the run begins. If deployment identity changes during execution, end the run as invalidated and start a new run after the new identity is frozen.