# Government and Public Sector 2.0.0 — troubleshooting

Every error carries a stable reason code. Find it below and follow the recovery step.

| Code | Meaning | Recovery |
| --- | --- | --- |
| `ENTITLEMENT_REQUIRED` | Your plan does not include this pack. | Start the Free Trial or choose a plan that lists the pack, then enable it again. |
| `PACK_INTEGRITY_UNVERIFIED` | The catalogue entry for this pack version has no integrity digest. | An operator re-registers the pack catalogue (register-pack) from a current image. |
| `PACK_DEPENDENCY_INACTIVE` | A pack this pack depends on is not active. | Activate the dependency first (GET /v1/industry-packs/government lists it). |
| `PACK_DEPENDENCY_NOT_CATALOGUED` | A dependency is not in the catalogue. | Contact support; the pack cannot be activated until the dependency is published. |
| `PACK_NOT_ACTIVE` | The pack is not active for your organisation. | Enable the pack, then retry (policy drafts, upgrade and rollback need an active pack). |
| `PACK_NOT_ENABLED` | A job or request names a pack that is not enabled. | Enable the pack, or remove it from the request. |
| `PACK_TEMPLATE_KEY_REF_REQUIRED` | A keyed masking template needs your key reference. | Pass key_ref (e.g. vault://…) in the policy-drafts body; the key stays in your secret store. |
| `PACK_TEMPLATES_UNAVAILABLE` | This pack version was registered without policy templates. | An operator re-registers the pack catalogue from a current image. |
| `UNKNOWN_POLICY_TEMPLATE` | A requested template code is not part of the active pack version. | Use the codes listed in GET /v1/industry-packs/government (policy_templates). |
| `PACK_VERSION_NOT_CATALOGUED` | The pinned or requested pack version is not in the catalogue. | Upgrade to a catalogued version (POST /v1/industry-packs/government/upgrade). |
| `PACK_VERSION_NOT_NEWER` | An upgrade must move to a newer catalogued version. | Pick a newer version, or use rollback to go back. |
| `PACK_NO_PREVIOUS_VERSION` | There is no earlier version to roll back to. | Nothing to roll back. |
| `AGENT_PACK_MISSING` | The job's agent does not have the pack installed (or does not report its packs). | Upgrade the agent to a release that ships the pack and reports installed packs, then resubmit. |
| `AGENT_PACK_VERSION_INCOMPATIBLE` | The agent holds a different pack version than the one active for you. | Upgrade the agent, or upgrade/roll back the pack so both versions match. |
| `AGENT_PACK_INTEGRITY_MISMATCH` | The agent's pack differs from the catalogued build (digest mismatch). | Reinstall the agent from the signed release image; never run a modified pack. |
| `AGENT_PACK_INTEGRITY_UNVERIFIED` | The catalogue has no digest to verify the agent's pack against. | An operator re-registers the pack catalogue from a current image. |
| `INDUSTRY_PACK_NOT_ENTITLED` | The job needs an industry pack that your plan or license does not include. | Enable the pack on a plan that includes it (see Billing & Plan in the console) or remove it from the policy. |
| `INDUSTRY_PACK_NOT_INSTALLED` | The job needs an industry pack that is not installed in this agent image. | Use an agent image that includes the pack, or remove the pack from the policy. |
| `JOB_AUTHORIZATION_UNAVAILABLE` | The control plane could not sign the job authorization your agent requires, so the job was not sent. No data was read. | This is a DataNivra service configuration issue; retry later or contact support with the job id. |
| `CERTIFICATION_FAILED` | One or more certification gates failed, so the dataset version cannot be published or provisioned. | Open the job's evidence in the console to see which gate failed (for example an uncovered sensitive column), fix the policy and request a new version. |
| `CERTIFICATION_REVIEW_REQUIRED` | A human certification review must accept this version before it is used. | Ask a reviewer to accept the version in the console. |
| `VERSION_NOT_CERTIFIED` | Only certified versions can be reviewed. | Wait for certification to complete or request a new version. |
| `DATASET_NOT_PROVISIONABLE` | Only certified versions can be provisioned; this version is not certified. | Certify a new version first. Failed or revoked versions never provision. |
| `EVIDENCE_INCOMPLETE` | The version's certification evidence is incomplete, so it cannot be used. | Request a new version. |
| `CERTIFICATE_SIGNING_UNAVAILABLE` | The control plane cannot sign test-data certificates (no signing key is configured), so builds are not dispatched and versions are not provisioned. No data was read or moved. | This is a DataNivra service configuration issue; retry later or contact support with the dataset id. |

Run `datanivra-agent doctor` on the agent host for value-free preflight checks (see `docs/runbooks/agent-doctor.md`).
