Found by smoking the served surface rather than by reading the code, and it contradicted a recon conclusion I had already accepted. ListsController resolves the composite subsite path - /sites/AngelsWorks/sites/Reception/Lists/Requests returns 200 - while HomeController returns 404 for /sites/AngelsWorks__Reception, because SiteDefinitionLoader derives blueprint names with Descendants and takes the RAW Name, so a subsite is only addressable flat, as though it were top level. The two nesting pairs that predate this cycle, OnetDemo__Team and Issues__Backlog, are broken the same way, so this is standing behaviour and not a regression. TWO CONSEQUENCES. First, the platform has a hierarchy for provisioning and feature targeting but a FLAT url namespace, which is accidentally close to what modern information architecture recommends and was reached by accident rather than by design. Second and worse, a subsite name must currently be unique across the entire manifest: a subsite named Reception was silently shadowed by the pre-existing ReceptionPortal, provisioned cleanly, and was simply unreachable. Decide which addressing scheme is authoritative, make both controllers agree, and fail loudly on a duplicate rather than shadowing.