You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Estimates are ideal engineering/operations days and exclude elapsed specialist review. P0 blocks V1.0; P1 is cut before a P0 slips. Owners are roles from the master plan.
Implementation ledger (2026-07-17)
This ledger records landed software scope without marking external evidence complete:
SRC-03/04/05: registry evidence/expiry/fetch-policy fields, derived anti-fabrication tests,
and the shared fail-closed predicate are implemented. The 152 real verification and policy
decisions remain human work under SRC-01/02.
SRC-03 writers (2026-08-15, #18): the record the predicate requires can now be produced by
the tooling rather than only read by it. sentinel verify writes the verification evidence
reference — a receipt of the page as the human was shown it — and the recheck expiry, and
sentinel sources policy writes the dated robots/terms decision with reviewer, evidence,
reason and expiry. Both refuse blanks. Neither makes the decision: the policy outcome is a
reading of somebody else's terms and is never inferred, which is why an absent decision stays
unreviewed and keeps the source out of the attempt denominator.
DATA-01: immutable normalizer/extractor contract versions are persisted on every new
snapshot and successful fetch attempt; a checksummed migration labels older snapshots
legacy-unknown, and database triggers reject invented or missing provenance. Release-trace
propagation remains open, so the backlog item is not complete.
DATA-04: every terminal fetch attempt persists its complete evidence — final URL and
per-hop redirect chain, distinct raw-byte/normalized-text hashes, byte count, byte bound
and truncation, MIME, extraction outcome, and a stable error class — with insert/update
triggers that make incomplete or fabricated evidence unstorable, legacy-unknown
labelling (never invented values) for pre-migration rows, and a restore-boundary test
that reads the evidence back from a copied database file. A distinct TLS-failure error
class is not implemented (TLS failures record as unreachable with the literal error
string), and the production encrypted backup/restore rehearsal remains OPS-02.
ENG-01: the ordered, checksummed, per-migration atomic framework plus run, attempt, and
run-observation entities are implemented. Remaining V1 review, correction, publication,
retention, and backup entities plus a production backup/rollback rehearsal keep the item open.
ENG-02: exact registry revision and eligible/attempted/successful source sets, persisted
attempts, atomic observation associations, race-safe terminalization, and constrained
quiet/complete/partial/failed receipts are implemented. Deployment, alerting, and qualifying
operational receipts remain open.
ENG-03: closed-schema aggregate status.json, derived stale health, separate
last-attempted/last-successful aggregate runs, explicit scope, and site health that ignores
scoped-only success and does not reuse generation time are implemented. Staging/production
evidence remains open.
ENG-04: substantive observations now require a distinct append-only independent decision;
same-actor, missing qualification/conflict evidence, returned, and insufficient review states
are structurally unpublishable. Real reviewer policy, calibration, authentication, and the
high-impact tabletop remain governance/operations gates.
ENG-05: append-only correction and withdrawal events, controlled reason codes, visible
schema-v2 lifecycle state, replacement integrity, and cycle-safe supersession are implemented.
Incident exercises, publication receipts, retention pins, and signed atomic releases remain.
ENG-06: the publisher now enforces the shared source predicate and canonical source identity.
Atomic promotion, signed manifests, and the clean verifier remain open.
ENG-07: the status schema and real-output compatibility test are implemented; correction and
release contracts and the complete migration guide remain open.
ENG-10: free-form first/second-review rationale and registry notes remain private; only
bounded observation copy and controlled lifecycle reasons serialize, prohibited legal-claim
terms fail closed, and legacy mutable notes are quarantined pending explicit audit. Counsel
approval of the templates and the real legacy-store audit remain open.
No line above substitutes for the acceptance receipt in the backlog table or the release
checklist.
Governance
Item
Pri
Est.
Owner
Depends on
Acceptance / linked requirement
GOV-01 convene paid community safety panel
P0
3
Governance
budget
≥3 qualified members, conflicts and authority documented
GOV-02 adopt reviewer qualifications, independence, and escalation
P0
3
Governance
GOV-01, counsel
calibration set passes; policy approved (REV-01/02)
GOV-03 counsel review of product claims, crawling, excerpts, privacy
P0
2
Legal reviewer
PRD/data map
written issues disposition; blockers closed
Source and evidence operations
Item
Pri
Est.
Owner
Depends on
Acceptance / linked requirement
SRC-01 verify every active source
P0
5
Verification
GOV-02
all active entries named/dated; skips remain ineligible (SRC-01)
SRC-02 resolve rejects, recheck-due, and active-but-unfetchable entries
P0
5
Verification
SRC-01
repair with reachable equally official source or structured gap; all six planning-time unfetchable active sources, including SS-5, have dated disposition before the operational baseline (SRC-01/02/PDF-01)
SRC-03 add verification expiry, fetch-policy decision, and eligibility rules
P0
2
Engineering
GOV-02
canonical registry stores dated robots/terms/fetch-policy reviewer, evidence, outcome and reason; redirect/authority/content sanity events trigger recheck; one predicate fails closed for unverified/recheck-due/policy-ineligible sources (SRC-01/02)
SRC-04 require verification evidence reference and migrate registry
PDF-01 implement bounded PDF extraction and manual comparator
P0
5
Engineering
DATA-01/04
every active PDF produces a cited passage comparison or labeled reproducible manual receipt; empty normalization cannot publish (PDF-01/DET-01)
Engineering and publication controls
Item
Pri
Est.
Owner
Depends on
Acceptance / linked requirement
ENG-01 introduce migration framework and V1 entities
P0
4
Engineering
data model
clean/current backup migrations and rollback rehearsal pass
ENG-02 persist run/attempt/source-health status
P0
4
Engineering
ENG-01, SRC-03
watcher uses the shared eligibility predicate; exact attempted/eligible numerator and denominator plus quiet, partial, failed, stale states are tested (DET-02/SRC-02)
ENG-03 expose status.json and accurate site health
P0
3
Engineering
ENG-02
generated time cannot masquerade as successful watch (DET-02/PUB-01)
ENG-04 enforce independent high-impact approval
P0
5
Engineering
GOV-02, ENG-01
same actor rejected; insufficient review unpublishable (REV-02)
ENG-05 add correction/withdrawal/supersession state
P0
5
Engineering
ENG-01, GOV-03
immutable history and cycle-safe links (PUB-02)
ENG-06 atomic release and signed release manifest
P0
4
Engineering
ENG-03/05, SEC-03, SRC-03
publisher rejects unverified, expired/recheck-due, policy-ineligible, rejected, withdrawn, and gap sources; interrupted build leaves old release intact; clean verifier validates hashes/signature (PUB-01/OPS-01/SRC-02)
ENG-07 schema/compatibility fixtures and migration guide
P0
3
Engineering
ENG-03/05
all artifacts conform; old major-1 fixture reads (PUB-01)
ENG-08 PII screening/quarantine before diff publication
P0
3
Engineering
data policy
seeded canary never publishes (PRIV-01)
ENG-10 separate internal rationale from constrained public copy
versioned target manifest covers registry/fetch/detect/changes/store/publish/verify, V1 health/retention/signing/migrations, and state-changing CLI handlers; CI reports each target and fails any below 95% while retaining ≥90% overall; no waiver
per-run gates pass; rolling objectives report available sample without premature quarter claim (OPS-01)
OPS-05 provision persistent runner and deployment path
P0
5
Operations + engineering
architecture, SEC-02
named host/volume/scheduler/static host/off-host backup; staging promotion, rollback and recovery receipts (OPS-01)
Release
Item
Pri
Est.
Owner
Depends on
Acceptance / linked requirement
REL-01 assemble traceability and release receipts
P0
3
Product
all P0
every checklist item dated, owned, linked
REL-02 multidisciplinary go/hold decision
P0
1
Release authority
REL-01
signed decision; hold if any must-pass fails
Execution order
The critical path is: GOV-01 → GOV-02 → ENG-04/10 → OPS-04, SRC-04 → SRC-01/02 → PDF-01, and ENG-01 → DATA-03/04 → ENG-02/05 → SEC-03/ENG-06 → OPS-05 → QA-01 → RC evidence. Source verification runs in parallel and finishes before any alert is treated as production-like.