You are machinery performing one bounded operation in a controlled production process. Use only the information supplied below. Do not plan other work, use tools, or decide what the pipeline should do next. Return only the requested JSON object.

OPERATION
Manufacture the security queue described by the product assignment from the incoming tickets. This is the initial product revision, so make the best report the supplied tickets support without inventing independent evidence. Return the complete report as Markdown in the `product` field.

RECORDED INPUTS
{
  "source_material": {
    "id": "ticket-set-001",
    "incoming_tickets": [
      {
        "id": "SEC-1841",
        "title": "Critical internet-facing RCE in payments gateway",
        "claimed_severity": "critical",
        "claims": [
          "Gateway Runtime 4.2 is installed in production.",
          "The legacy request parser is enabled on port 8443.",
          "An external scanner reached the production service.",
          "Planned work should stop until the gateway is patched."
        ],
        "reported_asset": "payments-gateway.example.com",
        "scanner_event": "scan-771"
      },
      {
        "id": "SEC-1842",
        "title": "Possible information disclosure in customer export service",
        "claimed_severity": "medium",
        "claims": [
          "Customer Export 2.8 is installed in production.",
          "A debug export route may be enabled.",
          "The route is believed to be internal and requires authentication.",
          "The finding can wait for the normal maintenance window."
        ],
        "reported_asset": "customer-export.example.com",
        "scanner_event": "scan-804"
      },
      {
        "id": "SEC-1843",
        "title": "High-severity legacy parser exposure on gateway-stage-03",
        "claimed_severity": "high",
        "claims": [
          "Gateway Runtime 4.2 is installed on gateway-stage-03.",
          "The legacy parser is enabled and reachable from the corporate network.",
          "The asset may be another name for the production payments gateway."
        ],
        "reported_asset": "gateway-stage-03",
        "scanner_event": "scan-771"
      }
    ]
  },
  "product_assignment": {
    "product": "Reviewed and prioritized security queue",
    "intended_use": "Help the team decide which reported vulnerabilities require attention first.",
    "instructions": "Consolidate duplicates, distinguish each service and environment, assess the reported findings, recommend proportionate action, and put the resulting work in priority order. Retain the source ticket IDs and state anything the available information cannot establish."
  },
  "acceptance_basis": {
    "id": "acceptance-basis-001",
    "criteria": [
      {
        "id": "attribution",
        "requirement": "Every conclusion is attributed to the correct service, environment and source ticket.",
        "tolerance": "blocking",
        "repair_group": 1,
        "depends_on": []
      },
      {
        "id": "duplicates",
        "requirement": "Tickets describing the same event are consolidated without losing their source identities.",
        "tolerance": "blocking",
        "repair_group": 1,
        "depends_on": [
          "attribution"
        ]
      },
      {
        "id": "applicability",
        "requirement": "Each finding establishes whether the affected component and vulnerable feature are present.",
        "tolerance": "blocking",
        "repair_group": 2,
        "depends_on": [
          "attribution"
        ]
      },
      {
        "id": "exposure",
        "requirement": "Internal and external reachability claims follow from evidence for the correct environment.",
        "tolerance": "blocking",
        "repair_group": 2,
        "depends_on": [
          "attribution",
          "applicability"
        ]
      },
      {
        "id": "severity",
        "requirement": "Local severity follows from established applicability and exposure rather than source labels.",
        "tolerance": "blocking",
        "repair_group": 3,
        "depends_on": [
          "applicability",
          "exposure"
        ]
      },
      {
        "id": "action",
        "requirement": "Recommended action is proportionate to the established local severity.",
        "tolerance": "blocking",
        "repair_group": 3,
        "depends_on": [
          "severity"
        ]
      },
      {
        "id": "priority",
        "requirement": "The final order puts the most important supported work first and does not count duplicates twice.",
        "tolerance": "blocking",
        "repair_group": 4,
        "depends_on": [
          "duplicates",
          "severity"
        ]
      },
      {
        "id": "limits",
        "requirement": "Missing evidence which could materially change a conclusion remains visible.",
        "tolerance": "blocking",
        "repair_group": 4,
        "depends_on": []
      }
    ]
  }
}
