Skip to content

Decision register and traceability

Temporary planning document. Planning only, not implementation approval. It lists what Chris has confirmed, what earlier designs recovered, what remains a proposal and what is still open, and where each item lands in the integrated plan. It changes no decision. The authoritative owner record remains the owner decision ledger. Where that ledger and this register disagree, the ledger wins and this register must be corrected.

Owner session (4–5 October 2026). §1.15 records the decisions and amendments of Chris's owner session. Its consolidation supersedes older conflicting recommendations, including earlier rows of this register; those rows carry an Owner session note and their text stays as history. Feature implementation remains on hold: these are planning approvals, separate from brief approval and implementation authorisation (per gate, D1-04, none given), and no work has started, no gate has passed and nothing is enabled in production. The owner-session integration holds the count reconciliation and the coverage matrix; the archive keeps the session outputs.

Precedence rules used throughout the package

  1. A later explicit owner decision supersedes an earlier one. Example: DP6/DP7 supersede the DP1 cross-stage wording that still appears in older sections of the stage/step handoff (lines 118–135). Likewise LC1/RX2 (3 October) supersede eligibility decision D3a (25 September) for the new stage model; that is recorded here, not asked again. In turn, the owner session of 4–5 October 2026 (§1.15) replaced DP6/DP7's cross-stage part with the stage study filter model (Q-15) and settled LC1's flow (Q-02); its consolidation supersedes older conflicting recommendations.
  2. Recovered baselines are earlier documented designs that Chris has not re-decided but that the ledger tells us not to reopen. Example: requireReanswer/autoUpdate/doNothing from Annotation Versioning §3.1–3.3.
  3. Proposals are recommendations from earlier drafts, from research (including COMPARISON findings) or from this plan. They need approval before implementation. Earlier drafts marked "UNAPPROVED PRELIMINARY MATERIAL" are inputs only. Their slices and defaults are not binding.
  4. Open items are genuinely undecided. Provisional assumptions are working assumptions this plan makes so that sequencing can proceed. Each one is listed in open questions and assumptions with the cost of being wrong.
  5. The v10 Claude Design pack and the April 2026 QM v2 planning are historical evidence. Their Open/Resolved labels do not override the ledger.
  6. Release names collide across documents. This plan's R0–R7 (with sub-releases such as R2a) are unrelated to FEAT-011's "Release ½/3" checklists, FEAT-001's release "R1", the QM v2 tracker's "R1/R2/R3" column and the "#2461 QM v2 R1 umbrella". The mapping of FEAT-011 checklist items to this plan's releases is in migration §7.

Evidence labels

Label Meaning
CODE-MAIN Verified in source on main at 78c6d097d (3 October 2026) and re-checked against 2949ca3a7
CODE-PR Present in an open, unmerged PR at a recorded head; not shipped
DOC-APPROVED / DOC-DRAFT Repository document with that front-matter status; not proof of implementation
OWNER Confirmed by Chris in the ledger, with ID and date
RECOVERED Earlier documented design the ledger says not to reopen
PROPOSAL Unapproved recommendation (earlier draft, research or this plan)
OPEN Undecided; listed in the open-questions document
ASSUMPTION Provisional working assumption made by this plan

1. Confirmed owner decisions

The plan column names the release (R*) or lane (L*) in the integrated plan that delivers each decision. "Engineering" means the behaviour is settled but its mechanism needs a design contract.

1.1 Shared forms, sessions and provenance

ID Decision (short) Plan placement Remaining engineering
SF1 A form is the project-level evidence/requirement owner. One reviewer-owned study/form session is reachable from every stage that uses the form. R2a (one stage), R2b (several stages), L1/L2 Form/version compatibility boundaries; legacy session mapping (E10)
SF2 The form owns its review target. A reviewer contributes once across stages, retries and corrections. R2a, R2b, L1/L7 Contribution derivation in statistics and allocation (C7, C8)
SF3 Compatible same-question/same-context answers are shared across overlapping forms; each form keeps its own completion. R2d, L1 Context identity contract (C2)
SF4/RE3 The target is a minimum. Every qualifying compatible effective assessment takes part in reconciliation; the UI must handle more than two candidates. R4a, L6 Scalable comparison layout (U1)
SF5 Show the reviewer's own prior answer and all ancestor answers across forms and stages, in the exact entity/branch context. Changing shared answers creates a new version and flags other sessions "contains outdated annotations". Fix explicitly creates a current incomplete session version and opens that session's form. R2d, L1/L5 Legacy duplicate-conflict detection, stale-base writes (E2)
SF6 A current Complete still counts despite an outdated-answer warning. A recorded action that creates a current incomplete version removes qualification until a valid Complete. R2d, L1/L7 Trigger catalogue per recorded action
SL1 Autosave preserves draft history without creating an explicit version on every edit. R2a, L1 Drafts contract (E21)
SL2 Save creates an immutable incomplete version. Complete validates and creates an immutable completed version. R2a, L1 Atomic version and receipt commit; applicability specification (E23)
SL3 The latest explicit Save or Complete is current. An incomplete Save after Complete removes completed qualification. Autosave alone never supersedes. R2a, L1/L7 Projection updates and readiness effects
PV1 Each annotation revision records source stage/step, stage-settings version, question version and the accepted-answer version actually shown. R2a, L1 Provenance schema (C3)
PV2 Stage settings are versioned and bind profile/form versions; historical work pins its requirements. R2a (minimal binding), R2b (several stages), R3a (steps), L4 Adoption and binding transition UX
GS1 Gold is an immutable, versioned snapshot per study referencing exact reconciled revisions. R4a, L6 Snapshot identity, pointer CAS and current selection (E8)

1.2 Versioning, publication and statistics freshness

ID Decision (short) Plan placement Remaining engineering
FV1 Adding a question creates a new form version. R2a (a used version never changes), R2c, L2 —
FV2 Publishing checks sessions under any prior version and prompts the admin to choose their treatment. R2c, L2/L7 Category-specific application (E1); two-phase publication (E22)
FV3 Whether earlier completed contributions count against the new requirements follows the admin's publish-time choice. R2c, L2 Reproducible counts
FV4 An admin may later revise an unnecessary update/re-answer requirement, with history; immutable versions and work are preserved. R2d, L2 Authority mapping; effects on already-performed work
Recovered Per-question requireReanswer / autoUpdate / doNothing, confirmed by the admin before commit (Annotation Versioning §3.1–3.3). R2c, L2 Application to completed, saved-incomplete and draft-only sessions; option mapping is Q-34. Owner session (5 October 2026): Q-34 is decided; the publisher explicitly declares compatibility and mapping (§1.15).
VU1–VU3 Invalidated answers stay visible as Needs updating; a valid replacement is required before Complete. Optional "Why it changed" and "What reviewers need to do differently" fields; a missing reason warns but never blocks. R2c, L2/L5 —
PS1 Use materialized, version-aware usage statistics for form versions and questions. R2c, L7 Stage-free usage family with the FEAT-024 owner (C8); production path is Q-31
PS2 Before publishing, make the relevant statistics current: wait for catch-up, refresh them in a targeted way, or briefly pause reviewing. R2c, L7 Protected boundary, fences, pause recovery (E3)
PS3 Publish only when the required statistics are current and the admin's handling choice is recorded; currentness must survive concurrent writes. R2c, L7 No timestamp-only race; authoritative affected identities

1.3 Visibility, blinding and exposure

ID Decision (short) Plan placement
VS1 Step-level "show reconciled answers to candidate reviewers", with a stage default. Own answers stay visible; other candidates' answers stay hidden. Amended by the owner session (Q-28, Q-30; OS-A04): reconciled-answer availability is a form baseline, on by default, shown as labelled hints with explicit click-to-fill; a step may only hide them; the stage default is superseded (§1.15). R3a (setting), R4a (gold exists), L4/L5
VS2 Agreement statistics separate independent answers from answers given after viewing gold; ordinary progress counts both; record the exact version shown. R4a (exposure), R5c (statistics), L6/L11
BL1 Reconciliation identity blinding is stage-owned and consistent across the workspace. Superseded by the owner session (Q-28, Q-30; OS-A02, OS-A03): the annotation form owns reconciliation identity blinding, and the screening profile owns it for screening reconciliation; blinded by default; context-local aliases; unpredictable candidate order (§1.15). R3a (setting), R4a, L6

1.4 Workflow, access and lifecycle

ID Decision (short) Plan placement Remaining engineering
DP6 Within a stage, the reviewer's own Include opens dependent steps, subject to a collective-Exclude veto. Cross-stage routing is configurable. Cross-stage part replaced by Q-15 (owner session): no cross-stage routing setting exists; the next stage's study filter defines its pool. Within a stage, own-Include progression stays the default (Q-01). R3a, L4 Propagation/concurrency (E5)
DP7 The cross-stage default is Collective Include required, with an advanced own Include sufficient option. Both keep the collective-Exclude veto. Optional strict within-stage collective mode is a proposal only. Replaced by Q-15 (owner session): the cross-stage default and its advanced option no longer exist. The strict within-stage collective gate is decided by Q-01: a stage setting, off by default. R3a, L4 Strict mode is OPEN (Q-01); interpretations Q-15. Owner session (5 October 2026): Q-01 is decided and Q-15 is replaced.
PR1 PRISMA reports the collective authoritative outcome: a collective Excluded stays Excluded even when extra extraction exists. Preserve that work and its provenance. R3a/R5b, L12 Report fixtures
EW1 Stage default Allow finishing previously saved work after collective exclusion, with an advanced per-step override (alternative: preserve only). Refined by the owner session (Q-28; OS-A05): default allow, with a step setting that can prevent completion; already-started work may also finish by default after any filter-driven pool departure, with an authorised admin restriction whose placement is still to specify (SP-AMB-01). R3a, L4 Surplus assessment record
DP2 A reviewer may deliberately correct their own Exclude to Include from their review history while review is still possible; new immutable submission; no automatic re-invitation. R3b, L3/L5 Exact controls (U18)
RX2 Recovered: automatic completion when all studies are resolved, automatic reopening when new studies arrive, manual mode, frozen completed bindings, drafts preserved, status history. R3c, L4 Runtime events not yet verified
LC1 Automatic completion also needs no unresolved applicable work, including drafts and corrections. Alert the admin and get confirmation before admitting a change that would reopen a Completed stage. Flow decided by Q-02 (owner session): an automatic Completed stage is recalculated when remaining work appears, with no confirmation hold; admin-initiated changes show their impact first and are rechecked at commit; protected changes to a Completed stage still need approval; manual completion stays until an explicit reopening. R3c, L4 Exact flow is PROPOSAL (Q-02); completion trigger (E29). Owner session (5 October 2026): Q-02 is decided.

1.5 Screening profiles

ID Decision (short) Plan placement
DP3 A rule-derived individual decision is confirmed only on explicit submission. Field changes and autosave never vote. Show triggering criteria and own answers as reasoning. R3b, L3/L5
DP4 Screening eligibility questions and configuration belong to their profile. Templates are copied, never live-linked. Stages sharing a profile share its answers; separate profiles never do. Reuse the question editor. R3b, L2/L3/L13
DP5 Profile On/Off toggle for exclusion-reason reconciliation. Off keeps recorded reasons and history; decision resolution stays separate. R3b/R4p, L3/L6 (E11 for the Off-collection combination)
RX1 Recovered: decision agreement and supporting-answer agreement are separate. Supporting-answer work appears in the reconciliation of a stage that uses the profile, without duplicate authority. R4p, L3/L6

1.6 Reconciliation, gold and queries

ID Decision (short) Plan placement
RA1–RA4 Shared pool by default. Optional assignment of a study to an eligible reconciler. Stage expiry default with audited override, applying only to explicitly assigned, unstarted work. Started assignments never auto-expire; admin release keeps saved work and requires reacquisition. Amended by Q-30 (owner session): expiry of explicitly assigned, unstarted work is optional, admin-configured and off by default; there is no stage default and no seven-day rule. R4a, L6/L8
RA5 Requesting one additional independent review after the target needs its own Request an additional review capability. The result returns to the reconciler, never sets gold and never changes the target. Superseded in part (owner session, consolidation §1): an additional-review request may name people or groups and many Studies, raises the effective Study × form target explicitly through an override version and counts qualifying reviewers once across routes. It still never sets an accepted result. R4a, L6/L8
RE1 Reconciled-answer explanations are optional, even when the answer differs from every candidate. R4a, L6
RE2 Final reconciliation submission accepts the valid displayed answers, including prefill. Autofill is clearly marked. Unseen relevant controls trigger a warning; Complete anyway is allowed. No per-field confirmation; validity is still enforced. R4a, L6/L5
RE4 One reconciliation task per study and form, reachable through any stage using the form; exact versions pinned. Screening-profile reconciliation is a separate part of the workspace. R4a, R4p, L6
RE5 Free text prefills only on exact text match in the same question/version/entity/branch context. No fuzzy matching or normalisation. R4a, L6
MG1 Suggest closest entity/cohort matches from labels and answers. The reconciler adjusts and confirms. v10 §4.3 scoring is a proposal; weights are not approved; no ML required. R4a, L6 (E7)
NT1 Contextual notes stay in candidate annotations; copies keep original authorship. R4a, L6
UA1 Required applicable questions cannot be blank in completed candidates; the reconciler decides optional blanks; blank is not N/A. Completeness scope/default and missing-state statistics are proposals. Owner session (5 October 2026): Q-04 is decided; completeness follows requiredness with a form override, and a blank comparison is Not assessed. R4a, L6 (Q-04)
QY1–QY7 Gold stays effective while queried, with a pending flag. One work item per accepted-answer version with per-concern outcomes. Resolve invalidated children before a replacement snapshot. Audited self-review is allowed for query reviewers, though a different authorised reviewer is preferred (QY4). Rejection explanation optional. Per-raiser private notices. Anyone who can view the answer may raise a query. R4b, L6/L14
QY8–QY9 A replacement that demonstrably satisfies a concern closes it as "addressed by update". Unsatisfied concerns stay open against their original target and are flagged for current-applicability review. R4b, L6

1.7 Agreement statistics, export and history

ID Decision (short) Plan placement
AG1 Viewing agreement statistics is a separate grantable capability; it does not come with Reconcile and never exposes candidates. R5c, L8/L11
AG2 Multi-select agreement requires identical selection sets; option overlap is shown separately. Agreement alone never publishes gold. R5c, L11
AG3 N/A+N/A agree; Applicable vs N/A disagree; compatible differing question versions are compared with clear flags; incompatible versions are not compared automatically. Missing/unanswered treatment is open. Owner session (5 October 2026): Q-04 decided the missing-comparison treatment (Not assessed, reported separately); formulas are specialist input T-SI-02. R5c, L11 (Q-04)
EX1 Current answers are the default download. Previous versions and the review state as of a date must also be downloadable. R2a (versions), R5a (as-of), L11
EX2 Include all recoverable history, including pre-migration data. No arbitrary cutoff, no fabricated legacy versions. R5a/R6, L11/L15

1.8 Permissions

ID Decision (short) Plan placement
PM1 Configurable project groups with project- and stage-scoped grants, under Members & groups with permission subsections. Ordinary admins get most or all ordinary permissions by default. Workflow actions get explicit permissions. Holding a capability is not the same as administering it. Ownership transfer stays outside the admin default. R1b (visibility, owner-only enforcement), R1c (groups), per-feature capabilities, L8
PM2 The owner can give permission administration to a group, deliberately extending today's owner-only AssignPermissions. Bounded, non-recursive delegation is a recommendation. R1d, L8 (Q-03)

1.9 Outcomes, templates and migration

ID Decision (short) Plan placement
OC1 The first outcome-schema release includes a legacy-compatible schema, an event-count schema and project schema creation/customisation. Field examples are not a mandatory bundle. Lane release O1, L10
OC2 / ODIR1 Direction ("greater is worse") is versioned metadata on the outcome measure, with one direction across cohorts in a paper/population and no context override. Different meanings need separate measures. It is never derived automatically from numeric type, and it is neither a numeric validator nor a treatment-effect claim. Conflicting legacy values need reviewed mapping. O1/O2, L10
TC1 Templates default to existing legacy entity types (disease model, disease-model intervention, treatment). Cohort, outcome-measure and experiment system types apply only when the extraction/export feature is used. C1/O1, L9/L10/L13 (E14)
MIG1 Outcome migration planning is authorised; execution is not. O2/R6, L15 (Q-05). Owner session (5 October 2026): Q-05 is decided-amended through R4 (universal baseline conversion); execution is still unauthorised.
IP1 Concrete implementation planning is authorised, not runtime code. This package

1.10 Setup and operations

ID Decision (short) Plan placement
SET1 Default screening-profile templates, an encouraged editable initial annotation form, ordinary question-library selection and optional guided preclinical setup. R1a, R2a, R3b, R3d, L13
SET2 Guided setup replaces CreateProjectWizard/ProjectSetup; it is not a parallel wizard. R3d; the old wizard retires at GA, L13
OPS1 Integrate existing materialized statistics, allocation, active-work tracking and batching, plus project/stage overviews and project/stage/step settings. All releases, L7/L16
NOTIF (3 Oct addition) Existing/current/planned notification infrastructure is in planning scope. Planning only; no notifications to project users. All releases, L14 (notifications integration)

1.11 Decisions from Chris's review of this package (3 October 2026)

These were given after the adversarial reviews, in response to the package. They are recorded here with the identifiers this package uses; the ledger should record them too when its owner next updates it.

ID Decision (short) Plan placement
UI1 UI design must be consistent and modern, and every new and updated UI screen uses Material 3. All releases: UI standard UI-1 to UI-11 and its width matrix (acceptance criteria §3); AC-ALL-08; C17
AC1 Well-defined acceptance criteria are crucial and must be in the plan. Acceptance criteria: Source and Status on every row; the traceability check fails on an uncovered decision (AC-S0-04, AC-ALL-16)
QD1 Permanently deleting a question is not allowed once it has been published under the new versioning system. R2a, C4; adopted questions count as published (migration §3)
SEC1 Fix the unenforced ownership transfer now: owner-only transfer, and no grants of owner-reserved activities. PR #3964, merged 3 October 2026, 85e6facf7; #3969 closed; R1b entry criterion
Q-10 Make the #3944 reconciliation-conversation changes (reviewer-private one-to-one threads, completed sessions only, exposure record, no editable context link, reconciler eligibility, conversations on their own flag). PR #3965, stacked on #3947
Q-07 Pilots are new projects and the seeded projects in the staging and preview environments; add seed projects where helpful. Acceptance criteria §6; plan §5.10
Q-08 Harvest the dormant QM v2 stack rather than revive it. F1a; plan §8; harvest map (5 October 2026)
Q-09 #2224's author has left; harvest its work into R1c. R1c; plan §8; harvest map (5 October 2026)
Q-13 As recommended: "Library" stays with Study Management; the question area is "Design"; the reusable collection is "question templates". R1a; C17
Q-03a As recommended: group create/edit under EditMemberships with anti-escalation; ChangeOwner never grantable; AssignPermissions only through R1d's envelope; Delete as Q-03 decides. R1c, R1d; C10
Q-25 As recommended: per-flag routes for production pilots. Plan §5.11
Q-31 As recommended: R2c production publication waits for FEAT-024 production readiness; for named pilot projects only, authoritative counting under the same protected boundary if gate (b) isn't reached when R2c is otherwise ready. R2c; C8
Q-06a Amendments A, C, D, G, H, I and J approved. Also incorporate ASySD deduplication inside SyRF, as described in the deduplication plans, and manual reporting of deduplication and other steps done outside SyRF for PRISMA diagrams. PRISMA amendments A–L; P1, P2, R5b

1.12 Decisions during the round-2 review (3 October 2026)

ID Decision (short) Plan placement
D1-01 Keep PR #3964 for the ownership-transfer fix. Port #3969's active-member check and its tests into #3964, then close #3969. (#3964 compares the caller with the persisted owner, so a stored ChangeOwner grant cannot bypass it; the policy #3969 relied on can be satisfied by such a grant.) PR #3964, merged 3 October 2026, 85e6facf7; #3969 closed; programme integration §9

Correction recorded against Q-25 (round 2, RT-02). Q-25's recommended route said active reviewer tracking is "not needed for slot-reservation claims". The code shows the opposite: claims, capacity guards and typed admission exist only when tracking is effective, and tracking is off in every deployed environment (on only in the E2E stack). Chris's answer to Q-25 stands for the other flags; the production route for claims returns to Chris as Batch D question D3-16 (open questions). Update (§1.15): the owner session made D3-16 a brief item (T-SP-00): shared-form capacity is piloted through admitted pilot projects first; it is no longer an owner question.

Answered by the evidence (no decision needed). The RA5 part of Q-10 (requested additional reviewers excluded from conversations until they return their review) is met by #3965's completed-sessions-only eligibility. One reconciliation task per study and form is already RE4; the round-1 "version-compatibility class" in the task key contradicted it and is corrected.

1.13 Batch D1 answered (3 October 2026, evening)

Chris approved D1-02 to D1-09 as recommended ("1-8. Yes I agree, approved", in reply to the eight recommendations listed after verifier V3). With D1-01 (§1.12), Batch D1 is complete. Each decision below is the recommendation's text in open questions.

ID Decision (short) Plan placement
D1-02 Precedence with the architecture-review roadmap (#3961): its Phase 0 security fixes continue; #3985 and #3973 are F1a prerequisites (X-ARCH-a); #3986 is decided before R0 guards PM consumers; #3988 is folded into E24 or deferred until after R2a; #3989 runs only as L5 seam slices until R3a ships. Plan §6.1 F1a entry; delivery operating model §15; programme integration §10, §12 (X-ARCH-a to d)
D1-03 ProjectStatistics (#3987): activate the families this plan uses, on a date set later (5 October 2026, §1.14); freeze is not chosen, so Q-31(b) is not extended to GA. Plan §6.1 F1a entry ("#3987 decided"); X-STATS-b1 to b7 on the GA path
D1-04 Implementation is authorised per freeze gate, not per PR: Chris approves each gate's dossier, including its slice list and decisions; merges keep his /approve, batched daily; he keeps every product decision, production enablement and adoption wave. Plan §6.1 "Authorises" column and §12; delivery operating model §2, §3
D1-05 Merge the owner ledger, this package and its research inputs to main now, as a docs-only PR (PR #3617); promote contracts into ADRs and feature specs as they freeze; keep one append-only ledger on main. G0 entry (step 0), met: PR #3617 merged on 3 October 2026 (f5318074d); plan §11 and §12
D1-06 Tester panel: five CAMARADES reviewers and administrators for T1 releases and three for the rest; sessions batched monthly; at least two external SyRF users where possible. The names were given later (§1.14). Acceptance criteria release tiers and §5; UX strategy §9; G0 exit
D1-07 Production opt-in pilots before GA: yes, for new projects whose creators opt in, after the release passes staging acceptance, R0 has completed a production soak and AF2 per-project admission exists; one production pilot per family (R2, R3, R4a) before GA. Plan §9 (pilots); acceptance criteria §5.2; A-23
D1-08 Write-path gate: zero engine-caused exhausted submissions at 1, 2, 5 and 10 concurrent reviewers (same study and different studies); absolute p95 budgets set after M0, starting at Save ≤ 150 ms and Complete ≤ 300 ms on a 200-question form; three benchmark tiers (50, 340 and 2,023 questions); E28 in pins and bytes. The start thresholds apply now; F1a confirms them from M0 evidence. AC-M0-02, AC-ALL-26, AC-R2a-19; M0 go/no-go; F1a
D1-09 Notification merge order: the ownership fix (done, #3964), then #3932 → #3938 → #3941 → #3942 (tolerant preferences) → #3943 → #3944 → #3965 → #3945 → #3947; restack #3965 onto #3944 if the stack owner agrees, otherwise keep it on #3947 and land it in the same train before any environment enables conversations. Notifications integration merge order; programme integration §8; X-NOTIF

What G0 still needs. These answers satisfy G0's "D1-02 to D1-09 answered". G0 itself is still Chris's approval of this package, and its entry and exit also need (step 0, D1-05, is met: PR #3617 merged on 3 October 2026): the Q-03 catalogue subset answered, D4-18's mapping part, the tester panel named (D1-06), a date for #3987's activation (D1-03) and the PR dispositions listed in plan §6.1; D3-14 and D3-15 too if S0-4 and S0-7 are to be enabled early. Nothing is built under this plan before G0 (D1-04). Update (§1.14): every input above was given on 3 October; G0 now needs Chris's approval of the G0 dossier, which also records the PR dispositions and the remaining exceptions (for example, the stream briefs are not yet written). Update (§1.15): the owner session decided D3-14 and D3-15 on 4–5 October 2026; G0 is still not approved and the implementation hold stands.

1.14 G0 inputs (3 October 2026, late evening)

Chris entered these on the programme status page between 23:08 and 23:23 BST on 3 October 2026. They complete the inputs G0 needs; G0 itself is his approval of the G0 dossier.

ID Decision (short) Plan placement
Q-03 Agreed as recommended: the permission matrix proposal is approved, with one rule: each new capability ships with the feature that uses it. The catalogue subset is settled now, so F1b can freeze C10; the Publish, stage-lifecycle and Monitor, and reconciliation subsets are approved as proposed and freeze with their features at F2, F3 and F4. C10; R1d; F1b, F2, F3, F4
D1-06 (names) Tester panel for T1 releases: Gillian Currie, Alexandra Bannach Brown, Francesca Tinsdeall, Chris Sena and Nadia Soleman. For other releases: Gillian Currie, Alexandra Bannach Brown and Francesca Tinsdeall. No external SyRF users are named yet; D1-06 asked for two "where possible". Acceptance criteria §5; UX strategy §9; G0 exit
D1-03 (date) #3987's statistics families are activated from 5 October 2026: staging first, then production the following week. The production date is a target: production enablement keeps its own approval (D1-04) and waits for the statistics readiness chain (X-STATS-b1 to b7). Programme integration §7; plan §8; GA path
D4-18 Chris chose a different answer from the recommendation: "independent of funders". Recorded reading (PROPOSAL until Chris confirms it in the G0 dossier): the plan maps the NC3Rs and SSI RSMF deliverables to releases itself and does not wait for the funders to confirm that mapping; the independent WCAG 2.1 AA audit at GA stays. G0 exit (mapping part); GA (audit)

The other decisions the round-2 reviews raised are Batch D2 to D4 in the open questions. None was decided until Chris answered. Update (§1.15): the owner session of 4–5 October 2026 answered, replaced or reclassified all but one of them. Of the 89 owner decisions open before it (Batch B 13, Batch C 15, Batch D 61), 63 are resolved, replaced, removed or deferred, 25 are alignment, brief or validation entries and 1 (D2-09) remains an open owner decision.

1.15 Owner session (4–5 October 2026)

Authority. Chris recorded these decisions in an owner session on 4–5 October 2026. The consolidation is the current text and supersedes older conflicting recommendations, including earlier rows of this register. A later explicit owner decision beats an earlier one. The archived session outputs keep the evidence, chronology and rationale (archive index). The owner-session integration holds the count reconciliation, the superseded-wording register and the coverage matrix, and the specification overview indexes the nine specifications. The owner ledger records the same decisions as Confirmed in its section "Owner session, 4–5 October 2026"; where the ledger and this register disagree, the ledger still wins.

Hold. Feature implementation remains on hold (Chris, 5 October 2026). These are planning approvals. Brief approval and implementation authorisation are separate, given per gate under D1-04, and none has been given. No work has started under them, no gate has passed and nothing is enabled in production; G0 is not approved. Nothing here authorises implementation, migrations, production activation, notification delivery, closing unrelated or dormant PRs, messaging the design session or building a new prototype.

Not newly approved. Permanent physical erasure (T-POL-01); a separate identity-erasure process (T-POL-02); automatic acceptance of several agreeing candidates (T-POL-03; Q-11's bulk acceptance needs an explicit reconciler confirmation); and every proposed numeric threshold, including D2-10's pause and operation limits, D4-21's F1 ≥ 0.99 and 80,000 citations in one hour, Unsure thresholds beyond the stated example and capacity-cap defaults. Exact PRISMA box mapping, statistical methods and scientific event definitions need specialist input (T-SI-01 to T-SI-05).

Counts (repository universe of 89). Before the session 89 owner decisions were open: Batch B 13, Batch C 15 and Batch D 61 (D2 16, D3 25, D4 20; D4-18 was answered at G0). The session register held 74 of them and the other 15 sat outside it. After the session:

  • 63 are resolved, replaced, removed or deferred: 52 from the session register and 11 outside it;
  • 25 are alignment, brief or validation entries, which are not owner questionnaires: 22 from the session register plus the engineering contracts D2-03, D2-04 and D2-06;
  • 1 remains an open owner decision: D2-09 (T-OI-01).

63 + 25 + 1 = 89. Outside the 89: the G0 items (G0-D1 confirming the D4-18 reading; G0-D4 to G0-D10 PR dispositions, with no closure authorised; G0 approval; lifting the hold), the policies above that are not approved and the amendments OS-A01 to OS-A30.

Vocabulary. Statuses are Decided, Decided-amended, Replaced, Removed, Deferred (beyond MVP), Brief item, Specialist input, Engineering contract (no owner question) and Open owner decision. Work status is tracked separately in the implementation tracker; today every work item is at most "Brief drafted". Specification columns name the owning specification: RD review domain and versioning, DM duplicate merge, SP stage pools, steps and history, RS reconciliation and screening, BC baseline conversion, TI training and inference, RI reporting, imports and AI screening, UX UX, devices and work discovery and ACD access, communications and deletion.

Decisions by package (the 52 resolved session-register entries)

"Foundations" are the Batch 0 and Batch B entries Chris answered before the condensed packages; the packages R1 to O4 cover the rest.

Package ID Decision (short) Status Specification
Foundations D2-11 Many drafts; one publication operation per form; the next publication rechecks the resulting state; collaborative drafts (OS-A01) Decided RD §3.7, §4.7
Foundations Q-20 Admin impact preview before publication; alerts to affected reviewers with drafts kept; in-form warnings for a reviewer's own edits; one deduplicated notice per recipient and cause Decided RD §4.8, §7
Foundations Q-27 Readiness from current evidence; warn the actor before commit; inform affected authors; dependent work never rewritten automatically Decided RD §4.5, §7
Foundations Q-34 The publisher explicitly declares compatibility and mapping; mapping writes attributable revisions Decided-amended RD §3.4, §4.8
Foundations Q-15 The stage study filter defines the pool; no incoming stage gate; dependencies are between steps; exclusion-stop is a separate step setting Replaced SP §3.3, §3.4, §5.1, §5.2
Foundations Q-24 Independent annotation stays independent; legacy stages map through the opt-in wizard; new combined steps stop extra screening at sufficiency (Allow available); Apply anyway releases temporary reservations only Decided SP §3.4, §3.11, §7, §10.4
Foundations Q-26 Immutable profile versions; mismatches with existing decisions and outcomes detected and treated before publication Decided RD §3.6, §4.12
Foundations Q-28 Form-owned blinding (profile-owned for screening reconciliation); reconciled hints as a form baseline with a step hide-only override; saved work completes after exclusion by default; form-owned timeout and in-progress limit; one shared place Decided (hint part Decided-amended) SP §3.9, §3.11; RS §3.5, §3.6, §5.6, §5.7
Foundations Q-12 Step selector with one form area in the existing annotation workspace Decided UX §3.1
Foundations Q-01 Progress after own Include while the collective result is pending; a stage setting can require collective Include; exclusion-stop still applies Decided SP §3.4, §5.2
Foundations Q-02 Automatic completion follows remaining work; static completion stays until explicit reopening; impact shown before admin changes; merges never change stage status directly Decided SP §3.10, §4.11, §5.9
Foundations Q-30 Hints on by default; blinding on by default with context-local aliases and no cross-Study continuity; unstarted-assignment expiry optional Decided RS §5.6, §5.7, §5.14
Foundations Q-33 A withdrawn search keeps its references and appends an event; current reports exclude it and explain; frozen reports unchanged Decided RI §3.5
Foundations Q-37 External-step ledger and deduplication QC adopted; the alias merge rule replaced by the consolidated Study (D2-12); parity numbers stay with D4-21 Decided-amended DM §4.1, §5; RI §3.4, §3.15
R1 Q-29 Target-one: automatic SingleAnnotator accepted result or required human reconciliation, configured on the form version; a task exists for every form Decided-amended RS §3.2, §5.1
R1 D4-03 Second-person checking is one-candidate human reconciliation; no Verified engine (OS-A28) Decided-amended RS §5.1
R2 Q-36 No ordinary self-reconciliation by default; explicit override grants; current authority for new admissions Decided RS §5.4
R2 Q-11 Optional per-form bulk acceptance, off by default, with explicit reconciler confirmation Decided RS §4.5, §5.5
R2 Q-32 A profile may require an adjudication rationale; off by default Decided RS §5.11
R3 Q-04 Completeness follows requiredness with a form override; blank is Not assessed; Unknown and Not reported are answers Decided RS §5.3
R3 Q-35 Legacy reconciliation backfill removed; every conversion dry run checks the no-records premise Removed RS §5.13; BC §4.2
R4 Q-05 Outcome data converts inside the faithful baseline; untouched defaults stay ValueOrDefaultUnknown Decided-amended BC §3.4, §4, §5
R4 Q-21 Legacy screening maps to a reviewed legacy-compatible profile; an admin confirms its meaning Decided-amended BC §3.4, §5
R4 D4-16 Early limited adoption only for complete, validated scopes; universal waves follow Decided-amended BC §5, §10.1
S1 D4-01 Per-profile Unsure, on in the title/abstract template; not excluded for availability; bounded handling (OS-A16) Decided RS §5.10
S2 D4-02 Optional discussion after a revealed conflict; initial observations kept; fallback when unresolved Decided RS §5.12
S3 Q-22 A primary reason is template and reporting guidance; distinct excluded Studies counted apart from overlapping reasons (OS-A17) Decided-amended RS §5.13
S3 D4-13 First failing criterion as the template default; per-profile reviewer choice Decided-amended RS §5.13
S4 D4-04 Training step with references, scoring, manual assessment, retries and optional group admission (OS-A18) Decided-amended TI §3.1 to §3.6, §5.1 to §5.4
S5 Q-18 First reasoner limited to conjunction, containment, disjointness and exhaustiveness; opt-in beta (OS-A19) Decided TI §5.5, §5.6
S5 Q-19 The Design capability publishes rules; reviewers confirm applicability; normal reconciliation resolves disagreement Decided TI §5.6
E1 Q-06b Amendments B, E and F: distinct units, coverage disclosure, frozen reports Decided RI §3.1, §3.2
E1 D4-11 Previous-review box from supplied counts; full updated-review workflow deferred Decided RI §3.4
E2 D4-05 Versioned search documentation; protocol record with append-only amendments Decided RI §3.6, §3.7
E2 D4-07 Explicit Sought, Retrieved and Not retrieved actions; a PDF never confirms retrieval Decided RI §3.8
E3 D4-09 Analysis-ready export, codebook and selected RIS; no effect sizes in SyRF Decided RI §3.9
E3 D4-10 Estimated-from-graph provenance now; digitisation after pilots Decided RI §3.9
E3 D4-14 Answer imports later; external and AI-model screening sources count by ScreeningSourcePolicy (OS-A20) Decided-amended RI §3.10 to §3.14
E4 D4-15 Accepted-answer branching between steps outside MVP; reconciled-answer filter clauses stay Deferred (beyond MVP) SP §3.4, §10.3
U1 D3-03 Labels accepted; "Draft auto-saved" versus "Version checkpoint saved", illustrative (OS-A21) Decided-amended UX §3.2
U1 D3-04 Material 3 sentence case Decided UX §3.2
U2 D3-05 Full annotation and screening on phones, tablets and desktops at launch; PWA exploration beyond MVP (OS-A22) Decided-amended UX §3.3, §3.11
U2 D3-06 Legacy screens refreshed with compatible features; workflow semantics unchanged (OS-A23) Decided-amended UX §3.4
U3 D3-07 My work, cross-project tab and global badge with notifications muted; landing page deferred Decided UX §3.5
U3 D3-08 Current tester panel; consent-based timing telemetry without answer content Decided UX §3.6
O1 D3-12 Search withdrawal keeps history; reversible project deletion and restoration (OS-A25); permanent erasure unapproved Decided-amended ACD §3.3, §4.5, §4.6
O1 D4-20 Contributions stay valid after access loss; admin exclusion by form, profile, stage or project (OS-A24) Decided-amended ACD §3.2, §4.3
O2 D3-22 Informative, permission-aware email; answers and free text configurable (OS-A26) Decided-amended ACD §3.5, §4.9
O2 D3-24 Per-project email mute; in-app notices kept Decided ACD §3.6
O2 D3-25 Conversations as permissioned audit records outside answer exports and agreement statistics Decided ACD §3.8
O3 D4-17 Outdated-answer handling configurable: warn and allow Complete (default) or block Decided-amended RS §5.8
O4 D4-19 Random serving by default; blinded, dynamic reviewer-pool browsing within a stage (OS-A27) Decided-amended SP §3.6, §4.5; RS §5.6

Decisions outside the session register (15 entries)

ID Decision (short) Status Specification
D2-01 Publication may create attributable generated session versions; reverses the round-2 "publication writes no evidence" proposal Decided-amended RD §3.15, §4.8
D2-02 Compatibility belongs to immutable question versions; SyRF suggests, the publisher declares; corrections use guided rollback and republication Decided-amended RD §3.4, §4.13
D2-05 The standard reviewer target is part of the immutable form version (OS-A12); every other setting is classified in the brief Decided-amended (in part) RD §3.5
D2-07 Form-owned inactivity timeout and per-reviewer in-progress limit; one place across tabs and routes; expiry keeps the draft Decided RD §3.11, §4.6; SP §3.11
D2-08 One shared session and place across tabs and devices; connections tracked separately; base-version checks; take-over presentation a brief detail Decided RD §3.10, §3.11
D2-12 One consolidated current Study with immutable history and reversible unmerge (OS-A29) Replaced DM (whole specification)
D2-14 Account deletion disables access and keeps named attribution; identity erasure not decided Decided-amended ACD §3.1
D2-15 One application-wide CAMARADES catalogue; versioned copies with provenance; publication requests Decided-amended ACD §3.4, §4.7
D2-16 No size-based exclusion; the largest project is an acceptance case Replaced RD-R33, RD §11
D3-14 Add missing staging seeds; prefer preserving staging data; justified staging changes allowed; never production Decided UX §3.12
D3-15 Firefox, WebKit and touch coverage Decided UX §3.12
D2-03 A data-type or multiplicity change is an incompatible version of the same question Engineering contract (no owner question) RD-R30
D2-04 A stage binds the form identity; the live route presents the session's resolved version Engineering contract (no owner question) RD-R31
D2-06 System questions stored as versioned data and adopted through a form publication Engineering contract (no owner question) RD-R32
D2-09 Shared-question accepted answers across two forms; recommendation unchanged: the second form's reconciler may revise with a new snapshot Open owner decision (T-OI-01) RD §4.14, §12

Alignment, brief and validation entries from the session register (22)

These are not owner questionnaires; genuine scientific or product choices found while writing a brief return to Chris. With D2-03, D2-04 and D2-06 above they make the 25.

ID Treatment (consolidation §7) Status Specification and tracker
Q-23 Apply the reporting-unit distinction; grouping of distinct reports deferred Brief item (carry-forward alignment) RI §3.1; T-RI-00
D4-08 Prepared multi-source links; Study-owned work; distinct-report grouping deferred Brief item (carry-forward alignment) RI §3.1; T-RI-00
D3-17 Capacity cap separate from the target; form baseline; no eviction; cap defaults proposed only Brief item (carry-forward alignment) SP §3.11; T-SP-00
D3-18 Form-owned timeout and in-progress limit; stage-derived rules removed Brief item (carry-forward alignment) SP §3.11; T-SP-00
D2-10 Tested publication active-work protection; measured pause and operation limits Brief item RD §7, §12; T-RD-00
D2-13 Isolated point-in-time recovery specification and rehearsal Brief item BC §8.4, §12.1; T-BC-00
D3-01 Material 3 roles and themes, dark-mode and staging checks, visual baselines Brief item UX §12; T-UX-00
D3-02 Design review checkpoints and risky-screen previews Brief item UX §12; T-UX-00
D3-09 Paused eligibility programme aligned with the filter and step model Brief item SP §12.1; T-SP-00
D3-10 Source-pinned statistics, protected pilots, profile granularity; production readiness provisional Brief item RI §3.17; T-RI-00
D3-11 Rebuildable agreement store with a source watermark and measured budget Brief item RI §3.16; T-RI-00
D3-13 Allocation and batch contracts; release, pool entry, review start and completion as distinct events Brief item SP §3.7, §12.1; T-SP-00
D3-16 Shared-form capacity piloted before broad rollout Brief item SP §12.1; T-SP-00
D3-19 Annotation place reserved at personal Include; screening kept when no place is free Brief item SP §4.6, §12.1; T-SP-00
D3-20 Active counts and own place for reviewers; Monitor names; blinding respected Brief item SP §6, §12.1; T-SP-00
D3-21 Notification environment, kind-family and pilot gates; test sink; delivery pause Brief item ACD §3.9, §12.1; T-AC-00
D3-23 Notices resolve with the work; unread counts consistent; history kept Brief item ACD §3.7, §12.1; T-AC-00
Q-17 Event-count field specification and the meaning of "variation" Specialist input RI §12; T-SI-01
Q-16 Denominators, percent agreement, statistical review of multi-rater formulas Specialist input RI §3.16, §12; T-SI-02
D4-12 Initial independent observations; per-profile screening agreement Specialist input RI §3.16, §12; T-SI-02
D4-06 Methodologist curation of the SYRCLE, CAMARADES and ARRIVE Essential 10 templates Specialist input RI §12; T-SI-03
D4-21 ASySD parity and performance method; F1 and throughput figures proposed only Specialist input RI §3.15, §12; T-SI-04

Amendments outside the register count (OS-A01 to OS-A30)

The session's additional agreed requirements. They add no entry to the 89; the owner-session integration assigns these IDs.

ID Amendment Status Specification
OS-A01 Collaborative question-management drafts: presence, live updates, conflicts, audit (supplements D2-11) Decided RD §3.7, §4.7; UX §3.8
OS-A02 Reconciliation blinding owned by the form or profile, with unpredictable candidate ordering (supplements Q-28, Q-30) Decided RS §3.5, §5.6
OS-A03 No cross-Study identity continuity in blinded reconciliation Decided RS §5.6
OS-A04 Reconciled-answer hints and explicit click-to-fill; step hide-only override; supersedes automatic prefilling Decided RS §3.6, §5.7
OS-A05 Already-started work may finish after any filter-driven pool departure by default; admin restriction, placement still to specify Decided SP §3.9; SP-AMB-01
OS-A06 A result produced through a stage may change its own pool: commit, then recalculate membership Decided SP §4.2, §9.2
OS-A07 Targeted pool-membership history; current pools stay query-time Decided SP §3.5, §4.1 to §4.4
OS-A08 Admin explanation of review activity and inactivity over time Decided SP §3.14; UX §3.7
OS-A09 Historical pool coverage for flow diagrams; actual review through the stage is the reporting priority Decided (box mapping is specialist input T-SI-05) SP §3.13; RI §3.3
OS-A10 Explicit entry justification for every pool entry Decided SP §3.5
OS-A11 Structured, queryable history events and the required event queries Decided SP §3.12, §3.13 (C20)
OS-A12 The standard reviewer target versions the form Decided RD §3.5, §4.9; RS §4.6
OS-A13 Configurable screening tie adjudication; member or group adjudicator assignment Decided RS §3.9, §5.11; SP §5.12
OS-A14 R4: explicit legacy activity mapping and adoption guidance in the wizard Decided BC §3.3, §4.3, §10.3
OS-A15 R4: universal faithful baseline conversion, then optional in-engine redesign; supersedes the permanent-archive option Decided BC §3.1, §4.6, §4.7, §10
OS-A16 S1: bounded Unsure handling and adjudication fallback Decided-amended (unstated transition rows are brief items) RS §5.10
OS-A17 S3: the exclusion-reason template is guidance and sets no question-count limit Decided RS §5.13
OS-A18 S4: training with reference answers, scoring, manual assessment, retries and optional group admission Decided TI §3.2 to §3.6, §5.2 to §5.4
OS-A19 S5: inference behaviour and the project-designer opt-in beta, off by default Decided TI §3.7, §3.9, §5.5, §5.6
OS-A20 E3: external screening and AI-model-generated screening decisions; model metadata ownership; source identity; terminology Decided RI §3.11 to §3.14 (C22)
OS-A21 U1: "Draft auto-saved" versus "Version checkpoint saved" (illustrative wording) Decided UX §3.2
OS-A22 U2: PWA exploration beyond MVP, including possible caching of allocated studies; no offline writes Deferred (exploration beyond MVP) UX §3.11
OS-A23 U2: compatible improvements on legacy screens without a workflow-semantics change Decided UX §3.4
OS-A24 O1: admin-controlled contribution exclusion Decided ACD §3.2, §4.3, §4.4
OS-A25 O1: reversible project deletion and restoration Decided ACD §3.3, §4.5, §4.6
OS-A26 O2: informative, permission-aware emails with configurable answer and free-text detail Decided ACD §3.5, §4.9
OS-A27 O4: optional, dynamic, blinded reviewer-study-pool browsing within a stage Decided SP §3.6, §4.5
OS-A28 R1: one candidate plus human reconciliation instead of a separate verification engine Decided RS §5.1
OS-A29 Consolidated, atomic, reversible duplicate merge; replaces D2-12's alias Decided DM (whole specification; C21)
OS-A30 Deliverable: the design-prototype handoff specification for iterating SyRF Prototype v10; no design session is messaged Decided (process requirement) Design-prototype handoff; T-DH-00

Earlier rows of this register. Rows in §1.2 to §1.12, §2, §3, §4 and §5 that these decisions change carry an Owner session note; their original text stays as history (§1.13 carries an update note too). §2 adds the superseded wording of the owner session (rows marked "Superseded wording 1" to "17" follow the main list in the owner-session integration).

2. Superseded wording that implementers must not follow

Superseded text Where it still appears Replaced by
DP1: personal Include carries across stages Stage/step handoff lines 118–135; parts of COMPARISON and research docs DP6/DP7. Owner session (5 October 2026): DP6/DP7's cross-stage part is itself replaced by Q-15's stage study filter model (superseded wording 5 below).
Per-step sessions and targets Earlier handoff drafts; v10 OD14/OD19 "Prototype currently" SF1/SF2
Completed stays effective until a new Complete Older lifecycle wording SL3
"Questions added: no impact on existing sessions" Annotation Versioning §3.2 FV1–FV3
One mutable pendingAnswer per Annotation as the draft model Annotation Versioning (In-Review) SL1; the C5 drafts contract (PROPOSAL)
Gold = "the latest annotation version on its reconciliation annotation" Annotation Versioning (In-Review) GS1 and QY3 snapshot gold
Single-annotator studies auto-promoted to reconciled ("SingleAnnotator") versions Annotation Versioning migration step 6; FEAT-006 design decisions; reconciliation data-model migration; QM v2 RECON-03, MIG-08 RE2/AG2 (gold needs an explicit final submission); target-1 path is Q-29. Owner session (5 October 2026): Q-29 (R1) now gives target-one forms a configurable automatic SingleAnnotator accepted result with system-rule provenance, or required human reconciliation; it is never labelled human reconciliation. Platform-wide and adoption-time promotion stay superseded; conversion creates no accepted results (RS-R04a NoAcceptance, PROPOSAL).
Rollback by $unset (FEAT-006 D18; FEAT-011 three-level model) FEAT-006 design decisions; FEAT-011 Canonical-aware rollback (research §5); FEAT-011 amendment I (approved, Q-06a)
Platform-wide backfill of lifecycle status and screening outcomes (MIG-11, MIG-12) FEAT-011 Phase 16 Per-project adoption (MIG1 planning, A-04); FEAT-011 amendment G (approved, Q-06a). Owner session (5 October 2026): per-project conversion inside universal baseline waves (R4; BC spec).
ScreeningOutcome with one stageId and no legacy authority value FEAT-011 lifecycle and source taxonomy Per-profile outcome with route provenance; amendment H (approved, Q-06a)
"Delete Study removes its Citations" FEAT-011 three-level model Reversible deletion; amendment J (approved) and Q-33
ASySD runs as an R subprocess FEAT-012 brief (Draft) The Approved FEAT-012 service specification: native C# implementation (amendment L)
FEAT-012 scenario 1 "delete secondary Study" FEAT-012 service specification, scenario table Secondary study kept with status Duplicate, as the scenario's own steps say (amendment L)
PRISMA identification counted only from imported records FEAT-011 flow mapping Reported external counts for steps done outside SyRF (amendment K, requested by Chris)
Agreed answers prefilled and individually confirmed (RD5, FEAT-006 "confirm each") v10 RECONCILIATION §1, §4.2 RE2
One reconciliation task per study × step v10 RD4 / RECONCILIATION §1 RE4 (study × form)
Blinding chosen per profile/form; "most restrictive wins" v10 RD7 BL1 (stage-owned); multi-stage tasks per Q-28. Owner session (5 October 2026): "most restrictive wins" stays superseded, and BL1's stage ownership is superseded too. The annotation form owns blinding, and the screening profile owns it for screening reconciliation (Q-28, Q-30; superseded wording 4).
Unversioned step reconciliation settings v10 RD3 PV2
Screening reconciliation always first; Exclude always hides form reconciliation v10 RD4/RECONCILIATION §1; QM v2 SCR-06 Configured dependencies and terminal policy under DP6/DP7; COMPARISON F4 is the research recommendation (PROPOSAL). Owner session (5 October 2026): configured step dependencies and exclusion-stop settings inside the stage (Q-15, Q-24; SP spec §3.4).
v10 step settings "who reconciles, per part"; "earlier gold … candidates never see it"; "EDIT RECONCILIATION reopens it" v10 RECONCILIATION Stage grants (C10); VS1; GS1/QY route. Dispositions in contracts, C9 (PROPOSAL). Owner session (5 October 2026): VS1 is now a form hint baseline with step hide-only narrowing (Q-28).
Selecting ordinary project questions as screening criteria Earlier recommendation DP4
System-catalogue-only outcome schemas in the first release 27 September restriction OC1
Open context override for outcome direction Earlier proposal ODIR1
Correction re-checks only the edited answer v10 RECONCILIATION §6 Not decided: COMPARISON F3 recommends the smallest supported dependency closure (PROPOSAL, R4b)
pmReference / ImportRecord three-level model QM v2 tracker ARCH-07, PRISMA-03 Publication/Citation/Study (CLAUDE.md domain model)
Angular 21 baseline v10 AGENTS/README, stage-review handoff, QM v2 FORM-01 Angular 22.1 (current package)
Eligibility D3a: no stage closure/reopening state machine docs/planning/review-eligibility-policy.md (In-Review, 25 Sep) LC1/RX2 for the new stage model, by the precedence rule. Owner session (5 October 2026): the lifecycle follows Q-02.
Eligibility D3b: annotation never needs a screening prerequisite Eligibility policy; ReviewEligibilityPolicyTests.cs:176 Kept for independent steps and migrated combined stages; DP6/DP7 for configured dependency edges (Q-24, A-16). D5 (excluded work) is unaffected. Owner session (5 October 2026): Q-24 is decided. Independent annotation stays independent unless a step dependency is configured; legacy stage behaviour maps through the opt-in wizard, where A-16 is a candidate mapping the wizard verifies; configured edges are steps inside a stage (Q-15).
FEAT-008 Included, Conflict pass-forward; FEAT-010 "stages unordered"; FEAT-026 "no sequential stage-step model" Feature docs (In-Review) and #3936/#3939 DP6/DP7. Owner session (5 October 2026): the stage study filter and step model (Q-15).
Global anonymised-candidate invariant; "Annotator A vs B" two columns FEAT-006 docs, AF2 README BL1 (stage-owned), SF4/RE3 (more than two candidates). Owner session (5 October 2026): blinding is owned by the form or profile and is on by default (Q-28, Q-30).
FEAT-001 D28: one global question collection for all AQs with scope and owner fields docs/features/annotation-versioning/README.md:614; FEAT-006 design-decisions.md:993 Project-scoped QuestionDefinition (record GUID, {ProjectId, QuestionId} unique) plus a system-scoped SystemQuestionVersion collection; principle 5 of the domain model (PH-16)
FEAT-001 D43: answer versions embedded in the Annotation document docs/features/annotation-versioning/design-session.md:360 Revisions in their own collection, never embedded (VB blueprint, domain-model §1.1)
FEAT-001 D49: no entity-instance concept; annotationId is the entity identity design-session.md:366 Entity instances exist: identity = the label head's ID in the author's scope, with rename, withdrawal and duplicate semantics (VB-09); E27 (PH-16)
FEAT-001 D50-revised: Study holds no back-references to annotations or sessions, to avoid contention design-session.md:367-368 Study.CanonicalSummary and the Study version bump in every canonical transaction (per-study serialisation, E20); contention is per study, not per project (PH-16, DC CR-1)
FEAT-001 D57: versions identified by (rootId, versionNumber), not GUIDs design-session.md:375 Revisions and versions carry GUIDs (client-proposed, validated) plus a per-parent Seq; aggregates with natural keys use deterministic GUIDs (E27, VB-16) (PH-16)
FEAT-006 D12: a rationale may be made required per stage docs/features/reconciliation/design-decisions.md:344, :977 RE1 (explanations optional); a required rationale exists only for screening-decision adjudication as a profile setting if Q-32 allows (PH-26). Owner session (5 October 2026): Q-32 is decided (R2): a profile setting, off by default.
FEAT-006 D15: no annotation reconciliation bypass design-decisions.md:980 Target-1 forms create no task (Q-29, PROPOSAL); bulk approve is Q-11 (PH-26). Owner session (5 October 2026): Q-29 is decided (a task exists; automatic SingleAnnotator or one-candidate human reconciliation, configured on the form version) and Q-11 is decided (optional bulk acceptance, off by default, explicit reconciler confirmation).
FEAT-006 D19–D27: reference-first cross-scope sharing, four ownership scopes, an Organisation aggregate, researcher libraries, a community Published flag design-decisions.md:984-992 DP4 and SET1: templates are copied, never linked; template scope per D2-15 (system catalogue plus project copies); no Organisation aggregate in this plan (PH-26). Owner session (5 October 2026): D2-15 is decided-amended: one application-wide CAMARADES catalogue with versioned copies, copy provenance and publication requests.
FEAT-006 D33: the reconciliation session is a materialised record on the study document, not an entity design-decisions.md:998 ReconciliationTask aggregate with a ReconciliationSession entity; gold as immutable StudyGold snapshots (GS1, RE4) (PH-26)
FEAT-006 D35: cross-stage disagreement resolved by the later stage's reconciler overriding design-decisions.md:1000 One task per study × form (RE4); shared-question gold is revised only with a new snapshot or by query (QY); whether only the first publisher owns it or the second form's reconciler may also revise it is per D2-09 (open) (PH-26)
Three releases and sixteen phases; "staging shares the same database" docs/roadmap/product-features-roadmap.md (Draft) lines 47–63, 295–304 This plan's release structure and the delivery operating model; the roadmap is replaced at G0 (PH-21)
Auto-promotion of single-annotator answers, rollback by $unset, platform-wide backfill docs/roadmap/migrations/release-2-migration.md lines 29, 40; release-3-export-prisma.md line 29 RE2/AG2; amendment I (canonical-aware rollback); amendment G (per-project adoption) (PH-21). Owner session (5 October 2026): target-one forms may accept automatically under Q-29; platform-wide backfill becomes universal baseline conversion (R4).
Random-only reconciliation assignment; "Annotator A/B" two-candidate view docs/user-guide-drafts/FEAT-006-reconciliation-workflow.md lines 31–36 RA1–RA5 (pool default plus explicit assignment), BL1, SF4/RE3 (more than two candidates) (PH-21). Owner session (5 October 2026): RA3 expiry is optional (Q-30); blinding is form- or profile-owned; additional-review requests raise the target.
Per-question pendingAnswer autosave as the AF2 draft model docs/features/annotation-form-v2/README.md lines 59, 193–204 SL1 and the C5 drafts contract (versioning model §7, consistency model §4) (PH-21)
Superseded wording 1 (owner session). Publication writes no evidence; no session version is created by the publication itself (D2-01 round-2 proposal) Versioning model §1.1, §2 rule 4, §7.3, §7.5, §8.1, §8.4, §8.5; consistency model §7.4, §19.3; contracts C4, C5; domain model §4.1, §4.5; integrated plan R2c; AC-R2c-02; open questions D2-01 and the Q-20 and D2-10 recommendations Publication may create attributable generated session versions, and SF6 applies to them literally (D2-01 Decided-amended; session register "Decisions already fixed"; RD §3.15, §14)
Superseded wording 2. Duplicate merge as an alias: two active Studies linked by mergedInto and StudyAlias; a split removes the alias; "moving Citations needs an identity and lineage manifest" (amendment D); "the admin's identity mapping is an alias" (FX-PRISMA-07a) Domain model §4.7, §6.2, §6.3, §7.1, §7.2, §9, §14; contracts C1, C9; consistency model §4.2, §7.8, §15, §19.3; prisma-amendments summary, D, L.4, L.5; integrated plan §5.8; versioning model §9.3; AC-P2-04, AC-P2-05, FX-PRISMA-07a; open questions D2-12, E33, Q-37 One consolidated current Study; originals kept as immutable history; atomic merge; reversible unmerge with per-item carry-forward choices; references never move (D2-12 Replaced; OS-A29; consolidation §2; DM §14; C21)
Superseded wording 3. The form target is an operational setting; changing it is an audited settings change that never triggers publication (D2-05 round-2) Versioning model §2 rule 6, §4.4; contracts C4; domain model §4.5; migration §3 stage-targets row; AC-R2a-33; FX-VM-42; open questions D2-05 A standard-target change creates a new immutable form version and uses the publication-impact process; Study × form overrides keep their own history (D2-05 Decided-amended in part; OS-A12; consolidation §1; RD §3.5, §14)
Superseded wording 4. Stage-owned or stage-only capacity, idle timeout and in-progress limits ("the most restrictive bound stage sets the cap and the idle timeout; the stage in use sets the in-progress limit; the form is tracked if any bound stage is"); "optional capacity cap (stage or route policy)"; most-restrictive-stage reconciliation blinding; BL1 stage-owned; stage-owned alias sources §1.3 BL1 above; owner ledger BL1; contracts C6, C7, C11, C15; domain model §4.4, §4.11; programme integration §6.2; ux-strategy §3.1; notifications integration §2; AC-R2b-10, AC-R2b-16, AC-R3a-15, AC-R3a-23, AC-R4a-30; methodology §2, §3.8; open questions Q-28, D3-17 and D3-18 recommendations Form-owned inactivity timeout, in-progress limit and capacity baseline with one shared count, where a stage may be stricter; reconciliation blinding owned by the annotation form, or by the screening profile for screening reconciliation, with context-local aliases (Q-28, Q-30, D2-07, D3-18; OS-A02, OS-A03; consolidation §4; SP §14; RS §14; ACD §14)
Superseded wording 5. A separate incoming stage-entry gate or cross-stage progression policy: DP6 "cross-stage routing is configurable"; DP7 "Collective Include required" by default with "own Include sufficient"; Q-15 parts (a) and (b); A-06 and A-18; the access-policy proposal's "Incoming dependencies / progression between stages" §1.4 DP6 and DP7 above; owner ledger DP6, DP7 and its header note; contracts C6 evaluation table; integrated plan §2, §5.5 (R3a); AC-R3a-05, AC-R3a-14, AC-R3a-21; access-policy proposal; open questions Q-15, A-06, A-18 The stage study filter defines the pool; dependencies are between steps inside a stage; exclusion-stop is a separate step setting; neither Q-15 alternative is approved (Q-15 Replaced; consolidation §3; stage-filters clarification; SP §3.3, §3.4, §14)
Superseded wording 6. Automatic prefilling of reconciled answers into a reviewer's form The earlier Q-28 owner-amendment wording in the session register; VS1-based display designs Labelled reconciled-answer hints shown by default, explicit reviewer click-to-fill, exposure and adoption recorded, never counted as independent evidence; RE2's matching-answer prefill inside the reconciler's own workspace is unaffected (Q-28 hint amendment; OS-A04; RS §5.7, §14)
Superseded wording 7. A mandatory "legacy authority unknown" reconciliation backfill; legacy reconciled answers exported as LegacyAuthorityUnknown (Q-35 recommendation) Contracts C9, C9-T14; migration §3; versioning model §11; domain model §7.2; AC-R4a-12; integrated plan §5.6; open questions Q-35 Removed; every conversion dry run verifies the no-records premise and stops that project's case on unexpected records (Q-35 Removed; consolidation §4; RS-R68; BC §4.2, §14)
Superseded wording 8. Permanent legacy or archive adapters; projects staying legacy indefinitely; completed projects kept as read-only legacy snapshots; "Reviewed adoption: existing projects chosen by Chris"; "Existing real projects stay legacy until R6 adoption"; staying legacy as a permanent R4 alternative Migration §2 adoption modes and §5; integrated plan §5.10; session register "R4 research finding"; condensed R4 options Universal faithful baseline conversion of every project after staging trials and production pilots; blocked projects record a blocker and remediate toward the baseline; legacy-writer retirement is its own verified, owner-approved milestone (R4; OS-A15; consolidation §5; BC §14)
Superseded wording 9. Immediate full report or investigation linking: a "link reports to one study" action (D4-08 original; amendment O) prisma-amendments §O; methodology §10.1; AC-R5b-15; open questions D4-08, E92 Prepared multi-source links; Study-owned work; distinct-report grouping deferred (D4-08 brief item; consolidation §1; RI-R03; RI §14)
Superseded wording 10. Account deletion anonymises the Investigator record and answers stay attributed to an anonymised identity (D2-14) Domain model §2.1, §3, §5; consistency model §11.5; migration §1 principle 8; open questions D2-14, E32; AC-R2a-30 Ordinary account deletion disables access and keeps named attribution; joining terms explain retention; identity erasure is not decided (T-POL-02) (D2-14 Decided-amended; consolidation §6; ACD §14)
Superseded wording 11. A separate verification step or session type producing Verified gold; the "single extraction, verified" export label (D4-03 original) Contracts C9, C14; domain model §4.3, §7.2; AC-R4a-49; methodology §3.1, §4.4, §5.8; open questions D4-03 The same reconciliation mechanism: target one plus required human reconciliation (ReconciliationPolicy.targetOneHandling = RequireHumanReconciliation) (R1; OS-A28; consolidation §4; RS §14; RI §14)
Superseded wording 12. An initial form-size ceiling; "the 2,023-question project stays on the legacy path even after adoption opens" (D2-16) Domain model §4.5; versioning model D2-16 row; open questions D2-16, E28; AC-R2a-22 No size-based exclusion; the largest project is an acceptance case, and E28 limits are engineered for it (D2-16 Replaced; consolidation §6; RD-R33; UX §14)
Superseded wording 13. A seven-day expiry for explicitly assigned, unstarted reconciliation work (Q-30 recommendation; RA3 stage default) Contracts C6; domain model §4.4; integrated plan §5.6; open questions Q-30 Optional, admin-configured, off by default (Q-30; consolidation §4; RS §5.14, §14)
Superseded wording 14. "Model decision" Earlier session drafts; new text must avoid it "AI-model-generated screening decision" and "AI screening model"; non-AI external sources keep their real source type (OS-A20; RI §14)
Superseded wording 15. "Changes kept, not yet saved" and "Autosaved—not yet submitted" ux-strategy §5.2, §6.4; domain model §8; acceptance criteria UI-11; open questions D3-03 "Draft auto-saved" for recoverable drafts and "Version checkpoint saved" after Save progress, both illustrative; the distinction is fixed and Complete stays distinct (D3-03 Decided-amended; OS-A21; UX §14)
Superseded wording 16. Every-ever-in-pool membership used as the PRISMA reviewed count Session register "historical pool coverage" section before the owner's clarification; prisma-amendments A; contracts C12 Actual review through the stage is the reporting priority; pool history is separate audit data; box mapping is specialist input T-SI-05 (OS-A09; consolidation §3; RI-R04; SP §14; RI §14)
Superseded wording 17. Every target-counted imported contribution must map to a SyRF reviewer (D4-14 original) Methodology §13.1; acceptance criteria §4.36 closing paragraph; contracts C3 imported authority; open questions D4-14 Configured external and AI screening sources count under the profile's ScreeningSourcePolicy; annotation imports keep the mapping rule (D4-14 Decided-amended; OS-A20; RI §14)
Owner session. A compatibility declaration may change until a revision pins the version (D2-02 recommendation) Versioning model §3.5; contracts C4; open questions D2-02 The publisher's declaration is immutable from commit; corrections use guided rollback and republication (D2-02 Decided-amended; RD §14)
Owner session. No autosave trail beyond the current draft (PH-33) Versioning model §7.6; contracts C5 Autosave sends diffs and keeps a reconstructable draft change log (consolidation §1; RD §3.10, §14)
Owner session. The second tab is read-only with "Take over editing" (D2-08 recommendation); a draft holds the place under today's idle and disconnect timers (D2-07 middle ground) Versioning model §7.6; consistency model §4.4, §4.5; contracts C5; AC-R2a-06, AC-R2a-37; open questions D2-07, D2-08, E21, E70, U31 One shared session and place across tabs and devices with base-version checks, where take-over is only a presentation option; form-owned timeout and in-progress limit; expiry keeps the draft (D2-07, D2-08 Decided; RD §14; UX §12 harmonisation)
Owner session. An additional review never changes the normal form target (RA5 boundary); a requested reviewer bypasses allocation buckets and the enforced target once (D3-13c); a requestedReview claim "never changes the target" Owner ledger RA5; §1.6 RA5 above; contracts C7, C9; domain model §4.3; programme integration §3.2; AC-R4a-38; open questions D3-13, E66 An additional-review request may name people or groups and many Studies, raises the effective Study × form target explicitly through an override version and counts qualifying reviewers once across routes (consolidation §1; RD §3.12, §14; SP §14)
Owner session. Q-34 option mapping OPEN; Q-26 OPEN ("a profile version publishes only before any decision exists") Versioning model §1.2, §5.1, §8.9, §15.1; AC-R2c-23 Decided: the publisher declares compatibility and mapping (Q-34); profile publication with mismatch detection and treatment (Q-26) (RD §14)
Owner session. StudyEnteredPool as the pool-entry event in StudyPoolLedger prisma-amendments A; domain model §4.2, §6.2, §6.3, §8, §10; consistency model §4.2, §12; programme integration §4.2; contracts C12; AC-R3a-05, AC-R3a-10, AC-R3c-17; open questions E26, E67 WorkFirstReleased for the first release of work (renamed to avoid clashing with stage-pool entry); StagePoolEntered and the other StagePool* events in HistoryEvent for membership (OS-A11; C20; SP §14; RD §14; RI §14)
Owner session. Merges refuse busy Studies (claims, drafts, open tasks) Domain model §4.7, §6.3; consistency model §4.2, §7.8 Warn about active work before confirmation, recheck at commit, keep drafts and refuse stale saves (consolidation §2; DM §7, §14)
Owner session. The current session is chosen (default the later Complete) and the other superseded; "primary and secondary Study" (dedup); scenario 4 links via a shared Publication without merging review data prisma-amendments L, L.4, L.5; FEAT-012 §7.1, §9.2; AC-P2-05; domain model §8; ux-strategy §5.2 The merging user or the original reviewer resolves both submissions in a reconciliation-like view and the actual resolver is recorded; "consolidated Study and input Studies"; related reports take the "distinct report" outcome (consolidation §2; DM §14)
Owner session. "Strict within-stage collective mode is a proposal only" (Q-01 open) §1.4 DP7 above; AC-R3c-07; integrated plan §5.5 (R3c) Decided: a stage setting can require collective Include; off by default (Q-01; SP §14)
Owner session. LC1's "obtain confirmation before admitting a change that would reopen a Completed stage" applied to automatic stages and new arrivals ("the same gate"); "exact flow is PROPOSAL (Q-02)" §1.4 LC1 above; owner ledger LC1; AC-R3c-03, AC-R3c-08; open questions E29, U10 An automatic Completed stage is recalculated as soon as remaining work appears; admin-initiated changes show their impact first; protected changes to the Completed stage still need approval; manual completion stays until explicit reopening (Q-02; consolidation §3; SP §14)
Owner session. "Circular references … are detected at save time" FEAT-008 Filters read preserved evidence only, so recursion cannot arise (SP §14)
Owner session. The interim recommendation to omit continuous membership history Session register only Targeted transition history with query-time current pools (OS-A07; SP §14)
Owner session. "Target-1 forms create no task and no automatic gold"; "single reviewer, unreconciled"; an optional "accept as gold" action Contracts C9; domain model §4.3; AC-R4a-31; integrated plan §5.6, §5.10; migration §3; AC-R6-08; open questions Q-29 A task exists for every form; automatic SingleAnnotator result or one-candidate human reconciliation, configured on the form version; converted target-one forms carry NoAcceptance (RS-R04a, PROPOSAL) (Q-29; RS §14; BC §14)
Owner session. "Candidates are always blinded; the stage chooses only the alias scheme" (D4-19 recommendation) AC-R4a-48; methodology §3.8; open questions D4-19 Blinded by default; names visible only by explicit form or profile choice (Q-30; D4-19; RS §14)
Owner session. VS1 as a step policy with a stage default (originally recommended off) §1.3 VS1 above; owner ledger VS1; contracts C6; AC-R4a-42; integrated plan §5.5; open questions Q-30, U16 The form baseline shows reconciled hints by default and a step may only hide them (Q-28, Q-30; OS-A04; RS §14)
Owner session. Outdated answers: a non-blocking warning only, with enforcement levels dropped (D4-17 recommendation) Methodology §13.4; open questions D4-17, E34 Configurable: warn and allow Complete (default) or block until addressed (D4-17; O3; RS §14)
Owner session. Profile rationale, Unsure and discussion settings on the profile head with no impact flow; the Unsure rules "Unsure + Unsure and Include + Unsure need a third vote; Exclude + Unsure is a conflict" Versioning model §5.1; domain model §4.5; AC-R3b-05; methodology §3.2 In the immutable profile version with Q-26 publication; the RS §5.10 Unsure table (RS §14)
Owner session. "No project setting permits self-reconciliation" AC-R4a-28 No self-reconciliation by default; an explicit override grant (Q-36; RS §14)
Owner session. A submitted replacement of an input decision makes an earlier adjudication inapplicable, and the outcome falls back to the candidate facet until re-adjudicated (25 September clarification, RECOVERED) Consistency model §8.4; AC ambiguity B1 The adjudication stays the current final facet, flagged InputsChanged, until an eligible adjudicator explicitly reconsiders it; the actor is warned and affected authors informed (RS-R58; Q-27; O1 amendment; RS §14)
Owner session. An outcome authority list of CandidateAgreement, Reconciled, Adjudicated, Admin, Imported, LegacyUnknown prisma-amendments §H; contracts C12; domain model §7.2 ScreeningOutcome.finalSource plus RI's composition fields; accepted results use SingleAnnotator, HumanReconciled, Adjudicated and MergeResolved (RS §14; RI §3.13)
Owner session. "Allocation is disabled on adoption unless AL1 is live" Migration §3; AC-R6-14 An enabled allocation regime blocks conversion until AL1 and is never silently disabled (BC-R17, PROPOSAL; BC §14)
Owner session. "Allow admin-initiated adoption for screening-only, unreconciled stages after R3b, reversible until the first canonical write" (D4-16 recommendation) Open questions D4-16; AC-R6-17 Limited pilot scopes only with complete validated reader and writer coverage; the first-canonical-write boundary applies to every conversion (D4-16 Decided-amended; BC §14)
Owner session. "Restore policy (D2-13, PROPOSAL until Chris answers)" Migration §6; consistency model §13.1, §19.3 Brief item D2-13 with BC §8.4 and a required rehearsal; production execution needs separate authorisation (BC §14)
Owner session. Calibration step "R3c (or after GA with the C6 admission hook reserved now)" and deferral to the hook only; "scored training against gold as an admission prerequisite" in the backlog; "a passed-training admission hook in C6" Methodology §2, §3.4, §16.4; contracts C6; AC-R3c-18; open questions D4-04 Training is in delivery scope with references, scoring, assessment, retries, group admission through the group contracts and explicit promotion; hook-only deferral needs a separate owner agreement (D4-04; OS-A18; TI §14)
Owner session. C2 "Inference and counts" with no activation rule; U4 "conservative inference" including "safe count/bounds checks" Integrated plan §5.8 C2 row; contracts C13; unified-annotation-classification-research §7 Beta, off by default, explicit project-designer opt-in, never enabled by baseline conversion; the first reasoner is limited to the four operators (Q-18; OS-A19; TI §14)
Owner session. "Machine-learning prioritisation or automated exclusion … no lane" Methodology §2, Screening row External and AI-model-generated screening decisions are in scope in a later opt-in lane; prioritisation stays out of scope (OS-A20; RI §14)
Owner session. Phone support for title and abstract screening only, with annotation on tablet and desktop first (D3-05 recommendation) ux-strategy §6.1, §8.2; acceptance criteria UI-6, §3.1; open questions D3-05, U33 Full annotation and screening on phones, tablets and desktops at launch (D3-05; UX §14)
Owner session. Legacy screens restyled "with no behaviour change" only ux-strategy §3.4; AC-GA-09; open questions U45 Restyle plus as many compatible new features as possible, with workflow semantics unchanged (D3-06; OS-A23; UX §14)
Owner session. "At least two external SyRF users where possible" as a testing requirement; timing telemetry "if D3-08 approves"; "Pending D3-0x" markers for D3-03 to D3-08, D3-14 and D3-15 ux-strategy §9, §10, §15.1 and inline markers; acceptance criteria §5.3, §5.4, AC-ALL-25, AC-UX-03; A-38 The agreed tester panel with no extra external recruitment now; telemetry approved with consent and without answer content; the D3 entries decided as recorded in §1.15 (D3-08; UX §14)
Owner session. "Notification emails and digests may name the project; never study titles, aliases, answers or free text" (D3-22 recommendation) Open questions D3-22; contracts C15; AC-ALL-30 Study titles allowed; aliases and content follow recipient permission and blinding; answers and free text configurable; rights checked at delivery (D3-22; OS-A26; ACD §14)
Owner session. "Deleting a whole project keeps ADR-014's physical removal with a tombstone" (D3-12 recommendation) Open questions D3-12; AC-P1-16; integrated plan P1 row, X-DEL row and programme table; domain model §2.1 Ordinary deletion is reversible; permanent erasure is a separate unapproved policy (T-POL-01) (D3-12; OS-A25; ACD §14)
Owner session. "An audited admin action can exclude a reviewer's contributions from a form" (D4-20 recommendation) Open questions D4-20; AC-R2a-45 Exclusion by form, screening profile, stage or project, with preview, reason, actor and time, and provenance-based stage scope (D4-20; OS-A24; ACD §14)
Owner session. "A CAMARADES-curated system catalogue (an application role), plus 'copy from a project I administer'" (D2-15 recommendation) Open questions D2-15; AC-R1a-10; domain model §4.5 One application-wide catalogue with versioned copies, copy provenance and publication requests; project-to-project copy awaits confirmation (AC ambiguity B5) (D2-15 Decided-amended; ACD §14)
Owner session. "Auto-resolve … Yes" and "Notification enablement" as open owner questions Open questions D3-21, D3-23; notifications integration §6 Brief items D3-21 and D3-23; G-NOTIF unchanged (ACD §14)

The inventory §6 gives the full list of existing documents and code to amend in each implementing PR.

3. Dispositions of earlier unapproved proposals

These earlier drafts were inputs. This plan's disposition is itself a proposal for Chris.

Earlier draft Disposition in this plan Why
Preliminary implementation sequence (M0–M8 slices; M1 ordinary pilot as first usable release) Revised. M0–M8 remain the semantic dependency spine for the common engine. Release boundaries were redrawn twice: first as R1–R7 plus lanes, then, after review, as small releases (R0, R1a–d, R2a–d, R3a–d, R4a/p/b/c, R5a/b/c) with separate freeze and ship gates. Chris asked not to impose earlier slices silently. Only one ordering is forced by a confirmed decision: queries need gold (QY act on accepted answers). Engine before profiles is a technical choice, not a decision: DP4 requires reuse of the shared editor and engine, not a sequence; canonical screening decisions need the engine, so the order is kept and labelled PROPOSAL. As-of export (R5a) and agreement (R5c) no longer wait for PRISMA identification or each other. See integrated plan §5.
Permission matrix Adopted as the proposal to approve (Q-03, with Q-03a in Batch A), with one change: new capabilities ship with the feature that uses them, never as inert switches Matches PM1/PM2 and the RBAC research; avoids exposing permissions that do nothing
RBAC research Adopted as background and acceptance cases Primary-source grounded
Lifecycle/gold settings Adopted as proposals for Q-02 (LC1 flow) and Q-04 (gold completeness, missing-state statistics). Owner session (5 October 2026): Q-02 and Q-04 are decided (§1.15). Settled policy is kept separate from mechanisms still to approve
Access-policy strict mode Deferred behind Q-01. R3a ships the confirmed defaults and advanced option; strict mode is designed so it can be added in R3c as a tighten-only setting. Assumption A-18 departs from this proposal's "personal policy + no own decision" rule (Q-15, part b). Owner session (5 October 2026): Q-01 is decided (a stage setting, off by default); the proposal's "incoming dependencies / progression between stages" is superseded by Q-15's model; A-18 is retired. DP7 marks strict mode a proposal; the full scope keeps it as a candidate, not a release blocker
Guided setup/templates Adopted with re-sequencing: question templates and import in R1a, initial form in R2a, profile templates in R3b, replacement wizard in R3d, extraction shape after O1 Follows real dependencies
Statistics/allocation/batching integration Adopted as the contract amendment list for the owning programmes (C7, C8), plus lane release AL1 for shared-form allocation. The plan doesn't take over their PRs. OPS1
Outcome migration plan Adopted as the proposal for Q-05, with the default-value rules added, sequenced as O2 after O1 and the PRISMA identity gate. Owner session (5 October 2026): Q-05 is decided-amended through R4; outcome data converts inside each project's faithful baseline. MIG1 authorises planning only
PRISMA A–F amendments Adopted as required amendments through the FEAT-011 change policy, extended with G–L and consolidated in PRISMA amendments. Chris approved A, C, D and G–J (Q-06a) and asked for K and L; B, E and F (Q-06b) remain open, before F6b. Owner session (5 October 2026): B, E and F are approved through E1 (Q-06b); K and L are approved through Q-37, with L's alias rule replaced (D2-12). Approved source specs are not silently changed
Publish-pause queued-retry UX Kept as a recommendation (U5), not built until approved. Owner session (5 October 2026): Q-20 approved the admin impact preview and reviewer alerts; the pause and retry mechanics are brief item D2-10. The ledger explicitly marks it unapproved
v10 IMPLEMENTATION_PLAN S0–S10 Superseded by this plan's lanes; v10 acceptance walkthroughs are reused as acceptance scenarios where they agree with the ledger COMPARISON F8: S0 too broad, S8 after S7 wrong, S9 too late, S10 missing dependencies

4. v10 register crosswalk (44 entries)

v10 ID Current status Plan placement
RC10 Split. Screening decisions: recovered, profile rules re-run after a submitted correction, with manual work only if still needed. Annotation-form gold: candidate agreement after a correction never confirms gold automatically; the reconciler's final submission is required (RE2, AG2, SF4, RE5) R4b, L6
RC9 DP5 settles the toggle; collection-Off combination is E11 R3b/R4p
RC6 Open UI choice: per-step Skip/handoff versus study-level Skip (U2) R3a
RC8 Open layout choice: population context placement (U3) C1
X2 TC1 settles template defaults; catalogue checks are E14 C1/O1
X3 RX1 recovered R4p
OD1 DP6/DP7 settle routing; strict mode is Q-01; profile-version evolution remains open (Q-26). Owner session (5 October 2026): settled by Q-15 (stage study filter and steps; no cross-stage routing) and Q-01; Q-26 is decided. R3a, R3b
OD2 Engineering: partial combined-step reservations (E5) R3a
OD3 DP2 settles R3b
OD4 SF4/RE3 settle participation: every qualifying assessment takes part, and SF4 forbids choosing a subset; what remains is display and performance for many candidates (U1) R4a
OD5 Recovered invariant: route warnings never reveal votes (U5 copy) R3a
OD6 PM1/PM2 settle the architecture; the matrix is Q-03; which transitions need explicit confirmation remains open R1b–R4a
OD7 DP4 settles ownership; storage representation is engineering R3b
OD8 DP3 settles R3b
OD9 OC1 settles initial scope; field specs are E12 O1
OD10 FV1–FV3 settle the publication check; schema-upgrade UX is engineering O1, R2c
OD11 ODIR1 settles O1
OD12 Follow-up breadth after C2: rule chaining, set algebra, ontology authoring, population merging and cross-type count solving; no release assigned (follow-up) After C2
OD13 Engineering: evidence-based legacy session mapping (E10) R6
OD14 SF1 settles R2a, R2b
OD15 PV1/PV2 settle R2a, R3a
OD16 Engineering and owner approval: cascade effects of cross-stage corrections (Q-27). Owner session (5 October 2026): Q-27 is decided. R3a
OD17 GS1/EX1/EX2 settle the intent; manifests are E8 R5a
OD18 RX2/LC1 settle; exact flow Q-02. Owner session (5 October 2026): Q-02 is decided. R3c
OD19 SF2 settles R2a, R2b
OD20 SL1–SL3 settle; drafts contract is E21 R2a
RD1 MG1 settles; weights E7 R4a
RD2 One-sided items keep provenance; RE2 acceptance applies; no per-field confirm. Prefill applies only to matching answers (RE2, RE5), so whether an item recorded by only one reviewer is prefilled remains open R4a
RD3 PV2 supersedes unversioned step settings R3a/R4a
RD4 RE4 settles R4a
RD5 RE2 supersedes R4a
RD6 RE5 settles R4a
RD7 BL1 settles. Owner session (5 October 2026): BL1 is superseded; the form or profile owns blinding (Q-28, Q-30). R4a
RD8 PM1 settles; Members & groups page is in scope (L8) R1b, R1c
RD9 RA1–RA4 settle assignment; bulk reassignment remains open R4a
RD10 Profile resolution routes: extra votes (R3a), RA5 capability (R4a), adjudication (R4p). Owner session (5 October 2026): a profile may route ties to extra review or to a separate adjudication step (OS-A13); additional-review requests raise the target. R3a/R4a/R4p
RD11 RE1 settles R4a
RD12 FV4 settles R2d
RD13 GS1 settles; "v2.1" is display only R4a
RD14 AG2/AG3 settle parts; formula and missing states remain (Q-04, E9). Owner session (5 October 2026): Q-04 is decided (blank is Not assessed); formulas are specialist input T-SI-02. R5c
RD15 Declared resolved in v10: outcome reconciliation matrix and dialog R4c
RD16 Declared resolved in v10: keep the shipped matrix/dialog/spreadsheet pattern Existing (CODE-MAIN: AF2 outcome summary matrix, cell editor with spreadsheet grid, graph-region assignment); extended in O1
RD17 Open: 4a+3a recommendation; must scale to more than two candidates (U1) R4a
RD18 AG1 settles agreement access; non-admin pool visibility follows Q-03 R4a/R5c

5. QM v2 requirement crosswalk (April 2026 tracker, 101 requirements)

The QM v2 requirements tracker is Approved planning context. Phases 1, 2, 2.1 and 2.2 are documentation-complete; Phases 3–16 are pending. Code for M001–M004 exists only on open PRs (#2461, split as #2572–#2575) and was never wired to the API. The tracker's own "R1/R2/R3" release column is unrelated to this plan's releases. This crosswalk keeps every requirement group visible.

Group Disposition Plan placement
ARCH-01, ARCH-02 Complete (Phase 1). ARCH-02 refers to Angular 21 signal forms; re-verify against Angular 22.1 —
ARCH-03 (scope/owner/derivedFrom), ARCH-04 (Study optimistic concurrency), ARCH-05/06 (question and question-set collections) Retained as engine/versioning candidates; collection layout is decided in the C1/C2 contracts, not presumed R2a, L1/L2
ARCH-07, PRISMA-03 (pmReference, ImportRecord) Superseded by Publication/Citation/Study L12
PRISMA-01..04 Complete as the Approved FEAT-011 package L12
PRISMA-05..07, DEDUP-01..08, EXP-05/06 Retained in the PRISMA lane; amendments A–J apply (owner session, 5 October 2026: A–P) P1, P2, R5b
QM-01..05 (draft question, assign to disabled stage, DQ→AQ on stage enable) Revised: activation happens through form publication with impact prompts (FV1–FV3), not stage enablement R2a, R2c, L2
QM-06..12, QM-14 (structural/content split, AQV, QSV, ancestor integrity, library, history/diff, version badge) Retained (QSV becomes the form-version selection; see contract C4) R2a, R2c, L2
QM-13 (admin decision framework) Retained and extended to any prior form version, the three session categories and shared cross-stage use R2c, L2
FORM-01/02 (signal forms) Revised: AF2 on main is the reviewer form; reuse it rather than rebuilding L5
FORM-03 (per-question autosave creating AnnotationVersions) Revised by SL1: autosave is draft-only R2a, L1
FORM-04/05 (immutable SessionVersion with explicit revision IDs) Retained, adapted to form sessions shared across stages R2a, L1
FORM-06..08 Retained (FORM-08 candidate isolation is VS1); check AF2 parity and the stale virtual-scroll PR #3017 L5
PGRP-01..04 (custom groups; backend in PR #2224, incomplete frontend) Retained under PM1/PM2 R1c, L8
RECON-01, 02, 04, 05 Revised to GS1 snapshots and SF4/RE3 participation R4a, L6
RECON-03 (SingleAnnotator auto-promotion when MinAnnotators = 1) Revised: no automatic promotion; target-1 path is Q-29. Owner session (5 October 2026): Q-29 is decided; a target-one form may accept automatically as SingleAnnotator, configured on the form version. R4a, R6
RECON-06 (random only, no claiming) Revised by RA1–RA4: pool default plus optional admin assignment. "Reconcilers still don't cherry-pick studies" is PROPOSAL (from RECON-06 and v10 r2) R4a
RECON-07 (annotators never see other candidates' answers) Retained as VS1 candidate isolation (with FORM-08) R3a/R4a
RECON-12 (anonymised candidate presentation) Retained as BL1. Owner session (5 October 2026): blinding is owned by the form or profile, with context-local aliases (Q-28, Q-30). R4a
RECON-08 (reconciler's own annotation) Retained, read through RE2: final submission is the reconciler's acceptance R4a
RECON-09 (bulk approve) Open (Q-11): not confirmed or rejected by the ledger. Owner session (5 October 2026): Q-11 is decided: optional, off by default, explicit reconciler confirmation. After R4a
RECON-10 (scope = current stage question set) Revised by RE4: study × form task R4a
RECON-11 (cross-stage visibility per stage) Revised by VS1: step policy with stage default. Owner session (5 October 2026): VS1 is now a form baseline with step hide-only narrowing (Q-28). R3a/R4a
RECON-13..16 Retained; formulas need approval (E9, Q-04) R5c
RECON-17 (optional per-answer rationale) Retained (RE1) R4a
SCR-01..05, SCR-07, FILT-01..05, STAGE-01..04 Retained, revised by DP4–DP7, RX1 and PV2. Owner session (5 October 2026): DP6/DP7's cross-stage part is replaced by the stage study filter model (Q-15). R3a, R3b, L3/L4/L12
SCR-06 (screening reconciliation must come first) Superseded by configured routing under DP6/DP7. Owner session (5 October 2026): configured step dependencies and exclusion-stop inside a stage (Q-15). R3a/R4p
MIG-01..07, MIG-09..14 Revised into the reviewed, per-project adoption programme (no blanket rewrite). Owner session (5 October 2026): universal baseline conversion after trials and pilots (R4). L15, R6
MIG-08 (single-annotator studies auto-promoted) Revised: no automatic promotion at adoption (Q-29). Owner session (5 October 2026): conversion still creates no accepted results (RS-R04a NoAcceptance, PROPOSAL). R6
EXP-01..04 Retained R2a/R5a, L11
SHARE-, AQM- (deferred v2) Still deferred; AQM-01 impact assessment is now core (FV2) R2c