Integrated review programme planning package¶
Temporary planning package for Chris's review. Planning is not implementation approval.
Chris authorised comprehensive implementation planning and independent adversarial review on
3 October 2026, and later asked for progress to be committed and pushed on this PR branch. No
runtime code, migration, deployment, notification or flag change was made by the planning work. It
was prepared by Claude Code on the Opus 5.5 model (claude-opus-5-5), with read-only research,
review and verification sub-agents (Opus and Fable) and drafting sub-agents whose output the
orchestrating session reviewed and merged.
Owner session (4–5 October 2026) and implementation hold. Chris worked through the remaining decisions in a separate owner session on 4 and 5 October 2026. Its bundle is archived byte for byte in owner-session-2026-10-05/, and PR #4045 integrates it into this package. Feature implementation is on hold (Chris, 5 October 2026). The package keeps three things apart:
- Planning approval. Chris's owner decisions approve the plan's direction. They authorise no work.
- Brief approval and implementation authorisation. Each workstream brief (
T-RD-00toT-DH-00in the implementation tracker) needs Chris's approval, and implementation is authorised per gate (D1-04). Both are on hold. G0 is not approved. - Work started, gate passed, production enabled. None of these has happened. Every work item is at most "Brief drafted".
Start here¶
- The owner session in plain English: the product-owner guide separates the baseline (MVP), the opt-in beta, deferred enhancements and specialist decisions, with examples.
- What the programme delivers and how: integrated plan §1, including "What changed in the owner session".
- What Chris needs to decide next:
- One owner decision is open: D2-09, how accepted answers to a question shared by two forms
are revised (tracker
T-OI-01). The recommendation is unchanged: the second form's reconciler may revise them with a new snapshot. - The owner-visible confirm items in the specifications, notably reconciliation and screening §12 (the default for target-one handling, converted target-one forms, the Q-36 override reading, own Unsure and progression, re-acceptance under automatic acceptance and the screening-annotation agreement bypass). Other specifications list theirs in their §12. They refine decided directions and are answered with each brief.
- G0-D1, confirming the recorded reading of D4-18 in the G0 dossier.
- G0 approval, then the lift of the implementation hold, which are separate decisions. Even after both, each brief needs Chris's approval before its work starts.
- Specialist inputs for methodologists:
T-SI-01event counts (Q-17),T-SI-02agreement methods (Q-16, D4-12),T-SI-03template curation (D4-06),T-SI-04ASySD parity method and thresholds (D4-21) andT-SI-05PRISMA box mapping for pool history versus review through the stage. - The PR dispositions G0-D4 to G0-D10 stay unanswered, and no dormant PR is closed. The harvest map says what each PR under G0-D4 to G0-D7, and the three R1a PRs, contributes and when it could close.
- Decision counts, with their scope: before the owner session 89 owner decisions were open (Batch B 13, Batch C 15 and 61 of Batch D's 71). Of those 89, 63 are now resolved, replaced, removed or deferred; 25 are alignment, brief, specialist or engineering-contract entries that the briefs settle; one is open (D2-09). The breakdown is in integrated plan §11 and the owner-session integration.
- How the plan was challenged: two rounds of independent adversarial review, every finding resolved in a matrix (round 1, round 2).
Read in this order¶
- Product-owner guide: the owner session's outcome in plain English, with practical examples.
- Owner-session integration: how the session's 74-entry register
and the other 15 open decisions map into the package's 89; the superseded wording and why; the
OS-A01toOS-A30amendment IDs; the coverage matrix from decision to specification, contract, criterion, release and tracker row. - Integrated implementation plan: destination, invariants, streams and lanes, small releases (S0, R0, R1a–R1d, R2a–R2d, R3a–R3d, R4a/R4p/R4b/R4c, R5a/R5b/R5c), lane releases (P1, P2, C1, C2, O1, O2, AL1, X1 and the owner-session lanes), the GA milestone, universal baseline conversion (R6) and legacy-writer retirement (R7); freeze and ship gates; ready queue; programme integration; risks.
- Specifications overview: the entity map, what loads and writes when, ID conventions and the index of the nine specifications:
- review domain and versioning (RD);
- duplicate merge and unmerge (DM);
- stage pools, steps, capacity and history (SP);
- reconciliation, accepted results and screening resolution (RS);
- baseline conversion, recovery and legacy-writer retirement (BC);
- training and inference (TI);
- reporting, imports and AI screening (RI);
- UX, devices and work discovery (UX);
- access, communications and deletion (ACD).
- Rollout plan: the dependency-aware placement of every capability, including the new lanes (TR1 training, XS1 external and AI-model screening, XA1 annotation-answer imports, RW1 redesign wizard), the PWA1 exploration beyond the MVP, deferred branching (BR1), the R6 conversion waves and the R7 retirement milestone.
- Implementation tracker: one durable row per brief, specialist input, unapproved policy, gate and implementation slice, with brief approval, implementation authorisation, PR status, evidence and blockers kept apart.
- Design-prototype handoff: a self-contained
specification and copy-ready prompt for iterating SyRF Prototype v10 (
T-DH-00). Writing it messaged no design session and built no prototype. - Acceptance criteria: numbered, testable criteria for every release with source and status, merge and activation criteria, release tiers, the Material 3 UI standard and UX metrics, pilot criteria and user-testing rubrics, test data, fixtures, invariants and contract conformance test IDs, and traceability with the acceptance tooling.
- Delivery operating model: one approver and an agent workforce; streams, gates and authorisation, S0 and the M0 walking skeleton, WIP limits, review tiers, CI budget, definitions of ready and done.
- Versioning model: the rulebook for questions, forms, profiles, sessions, drafts, publication, reconciliation and exports under versioning.
- Consistency model: concurrency rules, the commit protocol, idempotency, ownership markers, fences, durable effects, ordering and as-of, the consistency matrix.
- Domain model and new aggregates: bounded contexts and context map, today's and new aggregates, events, commands, policies, value objects, glossary.
- Programme integration: current state of allocation and pool partitioning, progressive batches, review eligibility, active reviewer tracking and claims, materialised statistics, notifications, authorization and the architecture review, with strategically recommended changes and the external joins.
- Harvest map: how the existing question-management work (QM v2, #2572 to #2575 and #2461), #2224, the template-import PRs and the related dormant PRs are reused, adapted or avoided, with tracker rows and closure gates (Q-08, Q-09). Planning only: nothing is ported or closed while the hold lasts.
- UX strategy: research plan, UX metrics, reviewer efficiency, copy deck, design system of record, accessibility, change management and design QA.
- Methodology coverage: the plan measured against a high-quality systematic review, with methodology additions as proposals.
- PRISMA and deduplication amendments: amendments A–P to FEAT-011 and FEAT-012 (P, external and AI-model screening sources, added by the owner session).
- Contracts: the twenty-two shared contracts: C1–C19, plus C20 (structured history events), C21 (duplicate consolidation and reversal) and C22 (external and AI-model screening sources) added for the owner session.
- Open questions and assumptions: decisions for Chris by batch with their owner-session statuses, engineering items E1–E99, UI validations U1–U45, assumptions A-01 to A-40.
- Decision register: confirmed decisions with placement, superseded wording, dispositions of earlier drafts, the v10 and QM v2 crosswalks.
- Source and status inventory: verified implementation on
main, open PRs, documents, flags, conflicting documents and defects found. - UI coverage comparison, notifications integration and migration, adoption and rollback.
- Reviews: round 1 (A,
B,
C, matrix);
round 2 (thirteen reviews, verifiers V2 and
V3, the
resolution brief that "brief §n" references in the
documents point to, and the matrix, all in
reviews/round-2/); the five read-only harvest audits of 5 October and their brief, inreviews/harvest-2026-10-05/. - Validation evidence.
- Owner-session bundle (archive): the consolidation, the 74-entry register, the condensed packages, the stage-filter model, the superseded Q-15 clarification and the design-handoff addendum, each with its SHA-256 checksum. The consolidation wins over every older text.
Review outcome in brief¶
Round 1. Three independent read-only reviewers raised 102 findings, including four Blockers. Every finding was resolved, turned into a question for Chris or recorded as a labelled assumption, and a fresh-context verifier's 20 further issues were fixed.
Round 2. At Chris's request, thirteen independent Fable and Opus reviewers covered the versioning model (twice), data consistency, domain-driven design, acceptance criteria, the past year's planning, whole-application UI and UX, delivery, systematic-review methodology, and the in-flight allocation, reviewer-tracking, statistics and notification programmes; a verifier checked the three documents added after round 1. They raised 362 findings, including 12 Blockers. All are resolved in the package or turned into Batch D questions with recommendations; none was rejected. The six new documents above and the rewritten contracts, plan and acceptance criteria are the result. A fresh-context verifier (V3) then read the whole package: it confirmed all 12 Blocker resolutions and found 33 cross-document drift findings (no Blockers), all of which were fixed. Details: round-2 resolution matrix.
Chris's decisions so far¶
3 October 2026.
- Fix ownership transfer now, in #3964 rather than
the duplicate #3969 (D1-01); make the #3944 conversation changes
(#3965). #3964 merged on 3 October 2026
(
85e6facf7) and #3969 was closed. - Batch A answered (pilots on new and seeded projects; harvest QM v2 and #2224; naming and group authority as recommended), plus Q-25, Q-31 and Q-06a, with ASySD and outside-SyRF counts added. Q-25's tracking line rested on a false premise and is corrected (D3-16).
- New and updated screens must be consistent, modern and Material 3; the plan must carry well-defined acceptance criteria; a published question is never permanently deleted.
- Batch D1 approved as recommended (D1-02 to D1-09): precedence with the architecture review,
activate ProjectStatistics, authorisation per freeze gate, merge this package to
mainas a docs-only PR, the tester panel's shape, production opt-in pilots before GA, the write-path gate, and the notification merge order. - The G0 inputs, late on 3 October: Q-03 as recommended (the permission matrix, with each new capability shipping with its feature); the tester panel's names (no external SyRF users yet); #3987's activation from 5 October 2026, staging first and production the following week as a target; and D4-18, "independent of funders", whose recorded reading Chris confirms in the G0 dossier.
These are recorded in the decision register §1.11 to §1.14.
Owner session, 4–5 October 2026 (consolidation; owner-session integration). Planning approval only.
- Counts with scope. The session's register held 74 of the 89 open decisions: 52 are resolved, replaced, removed or deferred, and 22 are alignment, brief or validation entries. Of the other 15, the session decided or replaced 11 (D2-01, D2-02, D2-05, D2-07, D2-08, D2-12, D2-14, D2-15, D2-16, D3-14, D3-15), 3 are engineering contracts with no owner question (D2-03, D2-04, D2-06) and 1 is still an owner decision (D2-09). Over the 89: 63 resolved, replaced, removed or deferred; 25 settled in briefs; 1 open.
- Main decisions. The standard reviewer target is part of the immutable form version; publication may create attributable generated session versions; a duplicate merge creates one consolidated current Study with a reversible unmerge; a stage study filter defines the stage pool, with no stage-entry gate and with dependencies between steps inside the stage; pool history and structured events explain review and non-review; a system adjudication step handles screening ties; Unsure handling is bounded; at a target of one, automatic Single annotator acceptance or required human reconciliation; training steps are in scope and inference starts as an opt-in beta; AI-model-generated screening decisions can be imported in a later lane; every project converts to a faithful baseline, and legacy writers retire at their own milestone; full annotation on phones, tablets and desktops at launch; the PWA exploration is beyond the MVP; answer-based step branching and report grouping are deferred; the mandatory legacy-authority backfill (Q-35) is removed.
- For the G0 dossier. D3-14 (staging seeds) and D3-15 (Firefox, WebKit and touch coverage) are decided, which answers G0-D2 and G0-D3. The current tester panel stays, with no external recruitment now (D3-08), which answers G0-D11. The production statistics date stays provisional.
- Not approved. Permanent physical erasure (
T-POL-01), a separate identity-erasure process (T-POL-02), automatic acceptance of several agreeing candidates (T-POL-03) and every proposed numeric threshold. - Implementation hold (5 October). Nothing authorises implementation, migrations, production activation, notification delivery, closing unrelated or dormant PRs, messaging the design session or building a new prototype.
Inputs and authority¶
- The handoff package (outside the repository, unchanged):
/home/chris/.codex/visualizations/2026/09/23/01a0cbec-0c32-7103-ab5a-bfc05665deb7/syrf-v10-review-2026-10-02/(PLANNING-BRIEF.md,COMPARISON.md,prior-plans/, the original v10 source pack undersource/design_handoff_syrf_v10/, evidence manifests and logs). - The owner ledger and the 2–3 October research and proposals are committed in this branch's
docs/planning/. - The owner-session bundle of 4–5 October, archived byte for byte with checksums in owner-session-2026-10-05/. Its consolidation is the current statement of the owner's decisions.
- Authority order: the owner decision ledger first, then recovered baselines, then proposals. Earlier drafts marked "UNAPPROVED PRELIMINARY MATERIAL" are inputs only. See precedence rules. Since 5 October, later explicit owner decisions beat earlier ones: the consolidation supersedes older conflicting recommendations and, where they conflict, earlier ledger entries; the archived session outputs keep the evidence and rationale. An assistant's proposal is never owner approval.
Package boundaries¶
- Implementation hold (Chris, 5 October 2026). Feature implementation is on hold. G0 is not
approved, no brief is approved and no work has started. Lifting the hold is Chris's separate
decision (
T-HOLD), distinct from approving G0 (T-G0), and each brief still needs his approval afterwards. - This package was merged to
mainon 3 October 2026 (PR #3617, merge commitf5318074d) under D1-05; later changes go through ordinary docs PRs. The G0 inputs and dossier followed in #4013, and the owner-session integration is PR #4045. - Lifetime (
PROPOSAL). This is a temporary planning package (docs/planning/is deleted when complete). As each contract freezes, its text is promoted into an ADR indocs/decisions/or a feature spec indocs/features/, and the package section points there. Once the GA milestone ships, the package moves todocs/planning/_archive/; it is deleted when R7 (retirement) ships, keeping the owner ledger's append-only copy onmain. The archive stop is a deliberate exception to delete-when-complete: adoption (R6) and retirement (R7) still cite its rationale after GA. - Live PR and programme states are a snapshot from 3 October 2026 (see programme integration §1) and must be rechecked before any implementation decision. The owner-session integration re-read none of them.