### Added - `docs/RUNNER-PROBES.md` documents the standing runner-probe venue, `heavy-duty/ceremony-runner-probe` — the place runner-only facts are measured on demand, ruled as option A by the operator (#202). - `drills/README.md` cross-links it beside the disposal rule, so the exception is visible where the dangerous habit lives (#202). - The runbook states that the drill disposal rule does **not** apply to it. Archiving it defeats its purpose, and that is exactly how the three existing drill repos each became unavailable (#202). - It records that a probe must run as an Actions job under the workflow token: the same call answers 500 there and 204 under a PAT, so a probe run any other way produces a confident wrong answer (#202). - Creating the repo is recorded as the operator's step, measured rather than assumed: a fleet identity gets 403 on org repo creation and 201 in its own namespace (#202). - It carries an executable arming procedure — fork ref, canonical SHA, both `CEREMONY_SELF_REF` carriers rewritten, and what the result must record (#202). - Probe results are written to an issue in the probe repo and carried to the ceremony issue by a human, so the probe holds no path that can write to the live board (#202).