### Added - `docs/RUNNER-PROBES.md` documents the standing runner-probe venue, `heavy-duty/ceremony-runner-probe` — the place runner-only facts are measured on demand, ruled as option A by the operator (#202). - `drills/README.md` cross-links it beside the disposal rule, so the exception is visible where the dangerous habit lives (#202). - The runbook states that the drill disposal rule does **not** apply to it. Archiving it defeats its purpose, and that is exactly how the three existing drill repos each became unavailable (#202). - It records that a probe must run as an Actions job under the workflow token: the same call answers 500 there and 204 under a PAT, so a probe run any other way produces a confident wrong answer (#202). - Creating the repo is recorded as the operator's step, measured rather than assumed: a fleet identity gets 403 on org repo creation and 201 in its own namespace (#202). - It carries an executable two-layer arming procedure: an immutable candidate code SHA and an armed workflow commit on top of it. A single layer is self-referential — rewriting a workflow makes a new commit, and a commit cannot contain its own object ID (#202). - Callers are pinned by layer: composite actions to the candidate code SHA, reusable workflows to the armed SHA, which is the only revision whose inner checkout points at the fork (#202). - The arming gate asserts what each carrier IS, not only that the old literal is gone: every `repository:` equals the fork, both `CEREMONY_SELF_REF` values equal the candidate code SHA, and callers match the layer they belong to (#202). - It enumerates the carriers from the tree rather than encoding a count, and distinguishes ceremony's internal self-checkouts from the consumer checkouts that must stay `${{ github.repository }}` (#202). - The published snippet parses, lints clean and runs: driven against an unarmed tree it refuses, naming the carrier (#202). - Probe results are written to an issue in the probe repo and carried to the ceremony issue by a human, so the probe holds no path that can write to the live board (#202).