Validation evidence¶
Temporary planning record. It lists what was checked while producing this package, how, and the limits. No runtime tests were run, because the package is documentation-only and the planning work was read-only. Sections 1–7 record the first round (early morning of 3 October 2026); section 8 records the second review round and the writes Chris later authorised.
1. Session and authority¶
- Model and effort: Claude Code on Opus 5.5 (
claude-opus-5-5) at maximum effort, as Chris requested; no other model was used for the main session. - Interruptions: the session was interrupted once to enable Remote Control and resumed in the
same conversation; it was later continued from a context summary. Both times the authorised task
(
claude-planning-launch-2026-10-03/prompt.txt) remained the governing instruction. - Authority: planning only. Chris's 3 October notification scope addition was incorporated as an additive, read-only planning update. No notification was sent and no notification PR was touched.
2. Workspace safety checks (read-only)¶
| Check | Command / method | Result |
|---|---|---|
| PR3617 worktree state at start | git status --short --branch |
Branch feat/research-screening-as-specialised-annotation-gxgahs, 0 ahead / 0 behind upstream, HEAD 0f4c764b2; pre-existing dirty research: 2 modified + 16 untracked planning documents, none edited |
| Other writer in the worktree | Scan of /proc/*/cwd; newest planning-document mtime |
Only this session's shell had its cwd there; the last prior write was 03:13, the check ran at 03:22. No clash. |
Effective wt configuration |
main/.worktreerc + main/.worktreerc.local |
worktreeParent=/home/chris/workspace/syrf/pr, pattern pr{number}.{slug}, branch prefix codex; no worktree was created, moved or deleted |
| Handoff package vs worktree copies | cmp and diff |
Identical except link-path rewrites in six documents and in COMPARISON ↔ syrf-v10-design-comparison.md |
| Main baseline | git rev-parse HEAD, origin/main; git ls-remote origin refs/heads/main |
First 78c6d097d. Later the main checkout was found at 2949ca3a7 and then c59d9d0f1, each equal to the remote and clean; it was advanced outside this session. This session never fetched, pulled or modified it. |
| Code changes since the baseline | git log and git diff --stat from 78c6d097d to 2949ca3a7 and c59d9d0f1, over src/libs, the API, the web app and env-mapping.yaml |
Only FEAT-024 work (fold slice 6, including a reservation claim-stage refactor that keeps claims keyed by stage and investigator, and #3955's question-answer staleness fix), an identity registration fix, auth-migration documents and the generated API client |
| Writes made | git status and file modification times at the end |
Still the same 2 modified + 16 untracked pre-existing documents (last modified 03:00–03:08 BST, before this session's first write), plus only the new folder docs/planning/integrated-review-plan-2026-10/; no existing file changed |
3. Live GitHub reads (read-only gh)¶
- About 03:30–03:50 BST:
gh pr list --state open --limit 250(131 open PRs), merged PRs since 15 September (--limit 300), andgh pr viewfor 47 in-scope PRs and the 8 notification PRs. - About 04:52 BST (03:52 UTC), after the reviews:
gh pr viewfor 41 in-scope PRs (state, draft, mergeability, author, head, base, updated time), repeated once so GitHub recomputed mergeability against the newmain. - About 05:48 BST (04:48 UTC), after verification:
gh pr viewfor 21 in-scope PRs and a list of PRs opened since 03:50 UTC (#3958 and #3959, both outside this plan's areas); #3955 had merged. - In round 1, no PR, issue, label, comment or review was created or changed. The writes made later at Chris's request are listed in section 8.
4. Sub-agents (all instructed to be strictly read-only)¶
| Agent | Purpose | Type / model |
|---|---|---|
| Theme A inventory | Question, annotation, forms, outcomes, classification, setup documents and code | Explore / Opus |
| Theme B inventory | Review workflow, operations, governance documents and code | Explore / Opus |
| Prototype asset locator | Older QM v2, newer question-interface and reviewer prototypes; found / not found | Explore / Opus |
| Backend verification | Domain and API implementation state on main |
Explore / Opus |
| Frontend verification | Angular implementation state on main |
Explore / Opus |
| Notification stack inspection | #3932–#3947, main email/SignalR baseline, provenance transcript excerpts |
Explore / Opus |
| Adversarial reviewers A, B, C | Independent critique of the draft package (reports) | Plan / Opus |
| Resolution verifier | Fresh-context check that the resolutions landed and the restructure is consistent | Plan / Opus |
5. Direct re-verification of load-bearing claims¶
Before the reviews:
ChangeOwnerunenforced:ResourceSecurity.json,ProjectController.cs:365-390,Project.cs:855-883,ProjectUpdateDto.cs:17.Optionalnever read on the server:AnnotationQuestion.cs:55, 227.- The reconciliation response maps all study sessions:
ReviewController.cs:1586-1628,StudyDto.cs:53-58. - Question deletion cascade and #3088 gap:
ProjectManagementService.cs:201-222. - The redesign-prototype folder contents on
main.
After the reviews, before adopting their claims (all held):
- Strict class maps:
StudyRepository.cs:3176, 3209, 3220registerScreeningInfo,ExtractionInfoandSessionTallywith noSetIgnoreExtraElementsanywhere in the file; onlyEntity.cs:21carries[BsonExtraElements]. - Deletion fails closed:
SearchController.cs:122, 134andProjectController.cs:410throwDeletionLifecycleUnavailableException;StudyRepository.cs:1129-1130says search deletion is disabled today; thedeletionLifecycleflag entry inenv-mapping.yaml. - "Reconciliation reserves nothing" (
StageReviewService.cs:153) and "Migrate legacy reservations before enabling review eligibility" (Study.cs:346). SystemQuestionVersionchanges system-question structure (AnnotationQuestion.cs:561-578).GreaterIsWorseis abool(OutcomeData.cs:39); client defaultsSD,mean,false(annotation-form-outcome-topology.ts:40-43).- The AF2 reconcile host is read-only and stage-review/preview hard-fail on reconciliation
(
src/services/web/CLAUDE.mdAF2 section, lines 353–356). - AF2 eligibility must read the generated selector (
annotation-form-v2-eligibility.ts:59). - Dockview layouts: per-reviewer capability slots and API validation
(
docs/architecture/dockview-layout-migration.md). - Impersonation edit mode admits side-effecting actions (
SupportImpersonationAttributes.cs). - The
studyAttentionflag admits conversations, study reports and authorised decisions (#3947'senv-mapping.yaml); #3945 and #3947 are stacked on #3944 (gh pr viewbase branches). - The authorization plan's G-D, WP9, WP11, WP-M1/M2 and D10
(
handover/2026-09-08-authorization-3335/PLAN.md). - All seven #2621 prototypes exist; the local classification site build exists; v10's default navigation mode is "steps" with the numbered Setup section (prototype navigation code).
- The PRISMA amendment and fixture definitions, the FEAT-011 release checklists, the outcome-measure clarification and the ledger's OC2/ODIR1 and QY4 wording were read in source.
6. Documentation validation¶
./docs/scripts/validate-docs.sh --verbose --skip-indexes, run in the PR3617 worktree.
--skip-indexes is required because the index check runs generate-indexes.sh, which rewrites
existing index.md files; this package must not modify existing files. The validator checks
front matter and that linked files exist; it doesn't check #anchors, so a separate read-only
anchor check was added.
| Run | When | Result for this package | Whole-repository result |
|---|---|---|---|
| 1 | Before every file existed | Files then present passed front-matter checks; 8 broken-link errors, all pointing at package files not yet written | 8 errors, 63 pre-existing warnings |
| 2 | Before the review files existed | 5 broken-link errors, all pointing at reviews/ files not yet written |
5 errors, 63 pre-existing warnings |
| 3 | After the resolutions | All 14 package files pass front-matter checks; no broken links | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
| 4 | After the verifier's fixes, 06:00 BST | All 14 package files pass front-matter checks; no broken links | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
| 5 | After Chris's 3 October decisions (new acceptance-criteria and PRISMA-amendment documents), about 07:30 BST | All 16 package files pass front-matter checks; no broken links | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
| 6 | After adding the domain-model document, about 08:50 BST | All 17 package files pass front-matter checks; no broken links; 59 anchored links resolve under both slug rules | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
Anchor check (scratchpad script, both GitHub and MkDocs slug rules): after run 3, 42 anchored links all resolved, one only under GitHub's rule, so it was rewritten without the anchor. After run 4, 42 anchored links resolved under both rules. After run 5, 58 anchored links resolve under both rules (the amendment headings were changed from em dashes to "X." so their anchors match in both renderers).
Consistency sweep after the verifier's fixes: no stale release, gate or ID names remain outside the matrix rows that describe them; every question ID referenced in the package is defined in the open-questions document.
Not checked: the Mermaid dependency graph wasn't rendered by a Mermaid tool; its syntax follows the earlier version of the same graph.
The same results are summarised in the resolution matrix.
7. Limits¶
- No runtime, browser, database or deployment checks were made. Flag states in environments come
from cluster-gitops
values.yaml; runtime overrides were not read. - The notification provenance transcript was read in targeted excerpts only; claims were checked against code.
- The Figma file, the remote classification site and Review Prototype v3/v5 were not available; the local classification build was found but not reviewed. Three #2621 prototypes (PRISMA workflows, study state, dashboard) were inventoried by review C and by heading, not read in full.
- Some reviewer claims were adopted with their evidence but not traced end to end (marked "per review B/C" in the inventory).
- PR states are snapshots from 3 October 2026, about 03:30–03:50 and 04:52 BST.
8. Round 2 (afternoon and evening of 3 October 2026)¶
Times are BST. Chris asked for the round-2 review at about 14:30 and added the in-flight programmes at about 14:55; at about 19:00 he asked for plan progress to be committed and pushed on the PR #3617 branch.
8.1 Sub-agents¶
All reviewers and verifiers were instructed to be strictly read-only; drafters wrote only to the session scratchpad, and patch appliers edited only this package.
| Agent | Purpose | Type / model |
|---|---|---|
| Verifier V2 | The three documents added after round 1 (report) | Plan / Opus |
| Reviewers VA, DD, UX, SR, AP, MS | Versioning concept, domain design, whole-application UI and UX, methodology, allocation and pools, materialised statistics | Plan / Fable |
| Reviewers VB, DC, AC, PH, DS, RT, NS | Versioning implementation, data consistency, acceptance criteria, past-year planning, delivery, active reviewer tracking, notifications | Plan / Opus |
| Drafters (4) | Versioning model, UX strategy, methodology coverage, domain-model revision | general-purpose / Fable |
| Drafters (4) | Consistency model, delivery operating model, programme integration, acceptance-criteria revision | general-purpose / Opus |
| Patch appliers (5) | Merged the drafters' patch files into the existing documents; this session reviewed each diff | sdd-worker / Sonnet (1), Opus (4) |
| Verifier V3 | Fresh-context whole-package check after integration (report; fixes in matrix §7) | general-purpose / Opus |
| V3 fix workers (6) | Applied verifier V3's fixes from one shared brief, each owning a separate set of files; this session read every report, spot-checked the diffs and re-ran the scans | sdd-worker / Opus (4), Sonnet (2) |
The thirteen reviews and V2 were saved verbatim in reviews/round-2/. The fix PRs (#3964, #3965)
had their own implementers and fresh-context diff verifiers under Chris's separate authorisation;
they are not part of this package.
8.2 Live reads (read-only)¶
- GitOps. The cluster-gitops repository, read at the remote head, has
materializedProjectStatisticsFold: truefor staging's API and project management services (Chris's 1 October pilot decision). This corrected review MS, which had read a stale checkout. - Production and staging databases. A read-only count found no project storing a grant of ChangeOwner, AssignPermissions or Delete. A read-only count of legacy reconciled sessions in production timed out on an unindexed field and was not retried; it is recorded as an off-peak task before F4.
- GitHub.
gh pr viewandgh pr listfor the in-flight programme PRs; the refresh time is in programme integration §1.
8.3 Writes made (all authorised)¶
- Commits and pushes on the PR #3617 branch only, from about 19:00 (Chris's request), including one
merge of
origin/mainwhose only conflict,docs/planning/index.md, was regenerated withdocs/scripts/generate-indexes.sh. The PR #3617 description gained a section on this package.mkdocs.ymlwas regenerated withdocs/scripts/generate-mkdocs-nav.pybecause PR CI's navigation check failed on the new planning documents; the generator only added their entries. - Follow-up issues #3997, #3998, #3999 and #4000, filed from this session.
- #3964: Chris authorised the fix and its shipping on
a passing review and green checks, and chose it over #3969 (D1-01). It merged at
20:27 BST (merge commit
85e6facf7) after an approving review on its head and green checks; its description gained links to the follow-up issues, its worktree and branches were removed, and #3969 received a comment pointing to #3964. - #3617, step 0 (D1-05, approved by Chris on
3 October): the title and description were refreshed and
/claude-reviewwas requested on head1c8b1e84c. The review gave a "comment only" verdict with nothing blocking; it said it had not read the full prose. Its two non-blocking suggestions were answered on the PR: the navigation is left to the generator, and the lifetime trigger is added in the follow-up. After the review settled and the checks were green (docs validation passed on that head), it merged at 22:42 BST (merge commitf5318074d). Its worktree and branches were then removed. - #4002, opened with
wt new: records step 0 as merged and adds the package's lifetime (PROPOSAL) to the README. - No notification was sent, and no runtime code, migration, deployment or flag change was made by the planning work.
8.4 Documentation validation¶
./docs/scripts/validate-docs.sh --skip-indexes --skip-links, plus the anchor script. The link
check was skipped in these runs because it is slow across the whole repository; the anchor script
checks every relative link with an anchor in this package, and the
validator run in PR CI checks links.
| Run | When | Result for this package | Whole-repository result |
|---|---|---|---|
| 7 | After integrating the round-2 documents, about 20:00 | All package files pass front-matter checks; 205 anchored links resolve | Exit 0; 0 errors; 64 warnings, none from this package (the 64th came from main in the merge) |
| 8 | After the acceptance-criteria cross-file patches and fixture-name fixes, about 20:20 | As run 7; every AC, FX and contract test ID cited in the package is defined, apart from labelled round-1 review IDs | Exit 0; 0 errors; 64 warnings, none from this package |
| 9 | After verifier V3's 33 fixes, about 21:10 | All package files, including the saved V3 report and resolution brief, pass front-matter checks; 236 anchored links resolve under both slug rules (one renderer-specific anchor removed) | Exit 0; 0 errors; 64 warnings, none from this package |
| 10 | After recording Chris's Batch D1 answers, about 22:34 | All package files pass front-matter checks; 260 anchored links resolve under both slug rules; no pending-D1-… status remains |
Exit 0; 0 errors; 64 warnings, none from this package |
8.5 Limits of round 2¶
- No runtime, browser, database-write or deployment checks were made.
- Reviewers' code citations were adopted where the resolving writer re-read them; the matrix marks where a claim was corrected instead.
- Live PR and programme states are snapshots from 3 October 2026 and must be rechecked before any implementation decision.
9. Owner-session integration (5 October 2026)¶
Chris's owner session of 4–5 October 2026 handed its bundle to this planning session, followed by an addendum asking for a design-prototype handoff. Times are BST. Feature implementation remains on hold; this round changed planning documents and the status page only.
9.1 Inputs and their integrity¶
- Bundle:
/home/chris/workspace/syrf/handover/owner-session-2026-10-05/. The coordinator'sverify_bundle.pyconfirmed its six manifest files; this session archived all 13 files byte for byte in owner-session-2026-10-05/ and re-checked every SHA-256 after staging (Git stores the Windows-line-ending file unchanged because the archive folder turns normalisation off). original-repository-register-input.mdis identical tomain's open-questions file at5245941e9apart from its Windows line endings (checked withtr -d '\r' | diff).- The original prototype was resolved from the owner ledger and the v10 pack's README: the Claude
Design pack SyRF Prototype v10. The three
.dc.htmlSHA-256 values were computed from the read-only pack and recorded in the design handoff.
9.2 Sub-agents¶
All drafters wrote only the files assigned to them; reviewers and verifiers were read-only. Every report was read by this session, which reconciled conflicts, applied mechanical fixes and committed.
| Agent | Purpose | Type / model |
|---|---|---|
| Specification drafters (5) | The nine specifications (RD, DM, SP, RS, BC, TI, RI, UX, ACD) | sdd-worker / Opus |
| Harmoniser | One editor across the nine specifications: 7 known and 21 further conflicts | sdd-worker / Opus |
| Phase 2 drafters (10) | Rollout plan and tracker; guide and overview; design handoff; register, open questions and ledger; plan, README and dossier; domain, contracts and versioning; consistency, migration and PRISMA; acceptance criteria; UX, methodology and programme documents; delivery operating model | sdd-worker / Opus |
| Integration drafter | The owner-session integration hub and coverage matrix | sdd-worker / Opus |
| Verifier V4, with four forks for checks 4 to 7 | Fresh-context, read-only check of the whole integration (§9.6) | general-purpose / Opus |
| Handoff fixer | V4's design-handoff findings, in that one file | sdd-worker / Sonnet |
9.3 Live reads (read-only)¶
ghreads of PR and issue states for the G0 dossier, the programme documents and #3510 (the statistics gate result of 3 October and Chris's soak-gate revision of 4 October).- Read-only source inspection: the web manifest and
index.html(PWA findings), the account deletion path (removePersonalDatais unread), anddocs/decisions/. ADR-014 is taken; ADR-021 was free at the first check, and #3961 took it for #3986's messaging ADR when it merged at 01:54, so ADR-022 is the next free number (git ls-tree origin/main docs/decisions/, 03:20). origin/mainmoved during the round (#4047, #4049, #4050, #3961). Onlymkdocs.ymlchanged on both sides; a trial three-way merge of it was clean.- The status page's database after republishing: the two recorded answers (Q-03, D4-18) and the
G0 inputs document are unchanged (
ArtifactData list, 03:29). - No database, cluster or production reads; no runtime builds.
9.4 Writes made (all within the request)¶
- Commits and pushes on PR #4045 only, in the
worktree
pr/pr4045.planning-owner-session-oct-4-5created withwt new.mainwas not changed. - The status page artifact was republished in place (version 3,
1791167435-1e02), keeping every recorded answer and G0 input. It now shows the hold, the owner-session statuses beside the original 91 items, 17 brief confirm items with recommendations, the 104-row tracker and the design-session prompt. A local browser load showed no console errors apart from the local server's missing favicon. - No design session was messaged, no prototype was built, no PR was closed and nothing was enabled.
9.5 Documentation validation¶
| Check | Result |
|---|---|
./docs/scripts/validate-docs.sh --skip-indexes --skip-links |
Exit 0; 0 errors; 64 warnings, none from this package (all 57 package lines are passes) |
| Relative links and anchors across all 58 package files, including the specifications, the archive README and the owner ledger (GitHub and MkDocs slug rules) | 2,498 links checked, 0 broken, after V4's fixes |
generate-mkdocs-nav.py and generate-indexes.sh |
Navigation regenerated for the new documents; indexes unchanged |
| Count reconciliation recomputed from the open-questions statuses | 63 + 25 + 1 = 89 (V4 recomputed the same figures independently) |
| Coverage matrix | 119 rows (89 decisions and 30 amendments), each with a specification section and a tracker row |
| Acceptance-evidence placement | All 288 specification evidence items placed (§9.8 of the acceptance criteria) |
| Archive checksums | 13 of 13 match the archived copies, the bundle originals and the committed blobs |
| Fresh-context verifier V4 | 24 findings (2 Blocker, 4 Major, 18 Minor); all fixed (§9.6) |
9.6 Fresh-context verification (V4)¶
V4 found the decisions, counts, tracker and archive correct and raised 24 findings. All were fixed in this round and checked by this session by reading the changed lines; V4 was not re-run.
- Blockers. AC-R3d-02 and AC-R4p-03 still required DP7 cross-stage routes, which Q-15 replaced.
Both are retired for AC-R3d-02r and AC-R4p-03r (stage study filters, steps and dependent clauses),
with §4.37 entries, traceability rows and counts updated (58 retired IDs, 51
rrows). - Major.
- The rollout plan exempted S0's seeds and browser projects from brief approval; it now matches the dossier.
- The status page was not yet updated; it now is (§9.4).
- No specification owned the distinct-excluded-Study count (Q-22, OS-A17). RI now has RI-R05a, RI §3.3 and RI-AE40, and AC-R5b-11 and both matrix rows were extended.
- The remaining-inputs list omitted the TI owner-visible items and G0-D4 to G0-D10. Both are added, together with the guide's suspend option and legal-review routing.
- Minor.
- D2-09 timing: wanted before F4, with both options carried otherwise.
- Vocabulary: Q-23's carry-forward label and the engineering-contract status for D2-03, D2-04 and D2-06.
- The ACD legend in eight documents.
- Retired names:
AdjudicationTaskin AC-R4p-01;Importedas an outcome value. - D2-12, merge and unmerge wording.
- Release placements: browsing in R3c; the TR1 and RW1 dependencies; Training as a planned lane rather than an MVP item in the guide.
- "Model decision" reintroduced.
- Prototype timing.
- Handoff wording:
- the narrowed "legacy" ban;
- reversible-deletion copy with no restore deadline, because ACD §3.3 keeps deleted projects indefinitely;
- separate "Later release" and "Not in MVP" badges (new input DH-U34);
- an OS-A legend;
- three
PROPOSALmarkings.
- PRISMA amendment ranges.
- RI §3.5 for search withdrawal.
9.7 Limits of this round¶
- The specifications, rollout plan and tracker are planning documents; nothing in them has been built, measured or piloted. Every numeric threshold remains a proposal.
- Live states are snapshots from 5 October 2026 and must be rechecked before any decision.
- The design handoff was written for the Claude Design session; it has not been sent or tried.
10. Harvest map (5 October 2026)¶
Chris asked how the existing question-management implementation fits the plan. The answer recorded in #4045's documents was Q-08 and Q-09 (harvest, don't revive), but #4045's new deliverables never mentioned the harvest. This round adds the harvest map. Times are BST. Feature implementation remains on hold; this round changed planning documents and the status page only.
10.1 Inputs¶
- The heads of 13 open PRs, fetched read-only as
refs/remotes/audit/pr<N>: #2461, #2572, #2573, #2574, #2575, #2224, #3934, #2781, #2387, #2986, #2987, #2629 and #2812. Their heads, states and sizes are in the harvest map §3. - The package on
mainatadf27893d(after #4045).
10.2 Sub-agents¶
| Agent | Purpose | Type / model |
|---|---|---|
| Audits A to E (5) | Read-only audits of the PR groups against the specifications, saved verbatim in reviews/harvest-2026-10-05/ | general-purpose / Opus |
| Writer | The harvest map, tracker rows, specification §15 sections (RD, BC, UX, ACD, SP), guide §19 and rollout §7.7 | sdd-worker / Opus |
| Verifier V5 | Fresh-context, read-only check of evidence, counts, tracker, boundaries, consistency and links | general-purpose / Opus |
The first launch of the five audits was stopped before any output at a usage limit, and the audits were re-run from the same brief.
10.3 Writes made¶
- Commits on PR #4061 only, in the worktree
pr/pr4061.planning-qm-v2-and-dormant-pr-harvest-map-e2ujxxcreated withwt new. - The status page was rebuilt with the 116-row tracker and republished in place, keeping its recorded answers.
- No PR was ported, rebased, commented on or closed. No review state changed.
10.4 Validation¶
| Check | Result |
|---|---|
./docs/scripts/validate-docs.sh --skip-indexes --skip-links |
Exit 0; 64 warnings, none from this package |
| Relative links and anchors across 65 package files (GitHub and MkDocs slug rules) | 2,559 checked, 0 broken |
generate-mkdocs-nav.py |
Navigation regenerated (harvest map added) |
| Harvest entries against the audits | 131 entries, one to one, same verdicts and effort grades (V5 recomputed: 6 Reuse, 41 Adapt, 35 Reference only, 49 Avoid; 5 outside the programme) |
| Evidence citations | V5 opened about 40 cited path:line @ SHA locations; all supported, except one count (20 test facts, not 22), now corrected in the map and noted on audit E |
| Tracker | 116 rows (10 brief rows, 106 others; 95 implementation rows); every cited row ID exists |
| Fresh-context verifier V5 | No Blocker, 1 Major (the guide described PR-C's deletion as having happened; it never ran), 12 Minor; all fixed |
10.5 Limits¶
- The audits read code; nothing was built or run, so test-pass claims in the PRs are unverified.
- E-D1's "two production documents" with stray groups was not re-checked against production.
- Effort figures are estimates for planning, not commitments.