Skip to content

Program audit — technical evidence and limits ​

This is the evidence companion to the program report, first checkpoint on 5 October 2026. The existing review inventory remains the only queue. The report is a projection and interpretation of evidence, not a new tracker.

Source receipts ​

Repository receipts:

  • docs/reference/2026-10/2026-10-05/program-audit-source-evidence.json: exact source passages, paths, line ranges and SHA-256 hashes captured before changing execution instructions.
  • docs/reference/2026-10/2026-10-05/program-audit-catalog.json: complete SQL, timestamp and literal MCP response for the read-only public catalog snapshot.
  • docs/reference/2026-10/2026-10-05/current-batch-answer-propagation.json: earlier bounded answer and hosted-publication receipt. Rechecking its source hashes establishes continuity, not a fresh hosted request.
  • docs/reference/2026-10/2026-10-04/review-reset-inventory.json: original queue and append-only updates, plus the new program_audit assessment. Historical row dispositions are preserved. not_examined never means the user has not answered.

The first source pass located and fully read the overview, five pillars, relationship matrix, conformance and six pipeline pages. The primary reviewer rechecked the quoted conflicts in the source receipt. This establishes document review coverage for those passages; it does not verify their database or deployed-code claims. The rest of the Markdown corpus and every vocabulary value still need their own assessments.

Confirmed documentation findings ​

FindingExact evidence in the source receiptClassification and next check
Source does not establish authorship, but older ownership guidance treats it as an owning-brand chaincollection-not-authorship, conformance-source-and-owner, relationship-coverageConflicting explanation. Recover the ownership rulings and distinguish source owner, subject brand, publisher, maker and permission owner before inspecting consumer behavior.
Generic containment versus typed grouping edgesgeneric-containment, typed-grouping-directionConflicting explanation. Recover approval scope; inspect actual edge storage, cardinality, cycle enforcement and readers.
Missing Concepts homemissing-concepts, original-deliverablesMissing explanation. Recover the craft-rulebook and audience obligations without treating every term as approved.
An open alternative appears as a failed conformance ruleconformance-open-predicate, conformance-guidanceConfirmed check-definition defect. Define approved predicate, timestamp and scope before refreshing measurements.
Moment parent context versus interval evidencemoment-context, feature-evidenceClarification required. Preserve parent context while testing explicit subject, feature, classification and credit evidence. No blanket rejection of earlier inheritance rulings.
Review-before-create versus automatic entity creationentity-review-gate, onboarding-auto-createDocumentation divergence requiring a code and live-path trace. Not yet a newly verified production defect.
Explicit routes versus fallback handlingrouting-contradictionInternally inconsistent capability description. Trace entrypoint, route selection, effective prompt and default behavior.
Older guard does not inspect every current review surfacechecker-agenda-scopeCoverage limitation: section-name filtering is not full approval-propagation verification. Add targeted negative controls; do not treat the old green result as full coverage.

Catalog snapshot ​

Captured at 2026-10-05T22:22:06.089Z, PostgreSQL 17.6. Literal receipt parsed into these inventory counts:

text
relations: 198 = 184 tables + 13 views + 1 materialized view
information_schema columns: 2296
constraints: 489
indexes: 598
routines: 268
non-internal triggers: 32
policy inventory entries: 209
unvalidated catalog constraints: 0
security-definer routines: 25

The column inventory uses information_schema; it is not a claim to include materialized-view columns. No unvalidated constraints does not establish that required constraints exist. Security-definer routines are audit targets, not automatically defects. Tables without primary keys include names suggesting snapshots; names alone do not establish their ownership, use or eligibility for deletion.

Still required: attribute defaults and identity/generated properties; enum/domain definitions; full policy expressions and grants; views/materialized-view definitions; functions, triggers and dependency closure; platform dependencies; index validity and usage; actual query plans; duplicates, cycles, orphan checks and sampled semantic data profiling. Complete catalog enumeration must be joined to code consumers and lifecycle rules. No application data was changed by this query.

Original scope and authority ​

The original July brief is docs/reference/2026-07/2026-07-24/bigprompt-arch.md. The original two rounds and ratification are in docs/reference/2026-07/2026-07-26/atlas-review-responses.md. Docs requirements remain in docs/atlas/PRD.md and docs/atlas/PLAN.md; original W2c/W2f/W4 commitments remain recoverable there.

The product authority remains docs/reference/chatgpt-desktop-study/prototype/PLAN.md and docs/reference/chatgpt-desktop-study/consumer-audit/BUILD-CONTRACT.md, including B01–B17, MR, CX and later communication amendments. The report links these commitments; it does not migrate or replace their task ownership.

The September audit under docs/plan/audit/2026-09-12-pipeline-architecture/ is prior evidence. Its PLAN, WHOLE-SYSTEM-PLAN and reports explicitly leave work unfinished. A source unchanged since its receipt may support a bounded conclusion; deployed behavior, query results and permissions require suitable current evidence. Earlier summaries alone cannot certify them.

The original five use cases now have separate child obligations beneath the existing use-cases document obligation. Concepts, craft rules, audience definitions and the substrate build gate remain linked to their original requirement IDs. Unmapped console cards and requirement details remain explicit scope-recovery work, not silently completed items.

Independent architecture criteria ​

Use concepts independently from their labels; distinguish broader/narrower relationships, associative relationships and collections when assessing the vocabulary. This is a review criterion drawn from the W3C SKOS Primer, not a proposal to require RDF or replace the current database.

Use declared constraints to inspect enforced integrity, and dependency catalogs to understand affected objects. A foreign key establishes a reference constraint, not the human meaning of the relationship. The primary references are PostgreSQL's constraint documentation and dependency catalog documentation, matched to the observed server major version.

Compare retaining and hardening the design, simplifying redundant mechanisms, and selective replacement against the same acceptance cases. Sparse data and old names alone justify none of those choices.

Completion boundary ​

The current assessment is deliberately conservative. A known historical approval remains recorded even if its current audit assessment is not_examined. No approval is inferred from update order. No implementation or acceptance status is promoted because a document builds. Coverage and evidence checks test these bookkeeping boundaries; the full system audit and independent challenge remain unfinished.

Continuity recovery checkpoint ​

docs/reference/2026-10/2026-10-05/continuity-source-recovery.json preserves selected exact user messages from the August review and September foundations conversations, with session IDs, message locations and timestamps. It also records the original round headings and substrate card IDs. This is selective source recovery, not a claim that every conversation was read. No July-native transcript has been verified; the founding dictation is a banked source.

graphics-continuity-joe-answer.json in the same reference folder holds the exact reply source, full pre-edit review snapshot and four independently mapped current recommendations. The first three old filter proposals remain superseded history. No complete section vocabulary or physical change is approved.

The existing inventory gains 28 original-round obligations, 24 substrate-card obligations and carry #88. Original queue rows and prior execution updates remain unchanged. New obligations start unexamined in the current audit dimensions; their historical approval is not negated. Marketing and asset-detail work is linked to the existing PRD owner rather than duplicated as a new task board.

The historical handoff's September opening and the master's older NEXT directions are confirmed continuity hazards. The new current execution entry supersedes their next-action instructions while preserving their evidence. Broad restructuring of the model remains gated on the findings review.

Continuity verification boundary ​

The local continuity checks and conservation receipt are in continuity-checks.json, continuity-conservation.json and continuity-render.json beside the source receipt. Prior queue rows, execution updates and rulings are conserved. Eight affected pages render at desktop and phone widths without document overflow; this is browser-width verification, not actual-phone acceptance. The bounded independent review found no HIGH or MED findings in the approval and inventory diff.

The broader continuity-close-check.json is red, not a completed-audit receipt. Its procedure checker still selects the historical September window and compares its old ledger dispositions against later commits. The build-freshness failure was recorded before committing the new source and build. The browser interaction check initially failed because the local Docs server was offline; the restart and rerun are recorded separately. These findings expose limits in the old closure machinery and must not be silently recast as full-program verification.

Individual approvals and older implementation proposals ​

current-approval-crosswalk.json connects 45 current obligations to exact approved choices in seven banked answer records and their recorded rulings. The source reply hashes are checked. Two mappings narrow a historical bundle to the relevant child choice: complete Product Detail Page meaning and the motion-identity heading. Other identifier changes reuse the existing recorded links. No parent bundle is approved by this mapping.

The inventory checker now accepts these explicitly reviewed mappings only when the exact source, ruling, approved choice and statement agree. Negative controls reject proposed answers, changed meanings, wrong sources, wrong rulings, duplicate targets and missing scope. This verifies record consistency; it cannot independently judge whether two meanings are equivalent. The primary source review supplies that judgment.

substrate-reconciliation.json retains the exact original text of all 24 implementation cards, selected earlier replies and applicable later rulings. It gives each a next action without treating semantic approval as migration authorization. The old product-to-brand promotion premise is superseded; the remaining bundled meanings retain conservative assessments. Historical counts and claimed shipped behavior in those cards are not current system facts.

approval-substrate-checks.json preserves literal test outputs, source checks and conservation results for this unit. The original 636 queue rows and the prior 95 execution updates remain unchanged. Current meaning assessments and new evidence are separate additions. Implementation and acceptance assessments are conserved. The same queue remains the only tracker.

The live goal control was checked as active during this continuation. Older blocked-control statements in dated handoffs describe earlier observations. Control status is not proof of completed audit coverage or a deployed outcome.

Campaign writers and recovery ​

The next bounded audit unit is recorded in campaign-writer-trace.json, campaign-writer-catalog.json and campaign-recovery-reproduction.py/json under docs/reference/2026-10/2026-10-05/. The earlier grouping receipts remain the source for the selected keys, indexes and all-row membership aggregate. New receipts preserve thirteen exact source passages, the consumer search and a fresh selected catalog response. This is partial workflow coverage, not complete deployed tracing.

The inspected writer paths are manual campaign APIs, generic admin table mutations, the synthesis script, its graph synchronization and company backfill, a fixed dogfood seed and a historical one-shot SQL seed. The intelligence entrypoint inspected in the preceding unit contains a campaign no-op. None of these observations establishes an autonomous incremental recognizer. Literal public routine-body search found no occurrences of the three selected junction names; dynamic identifiers and other schemas remain outside that conclusion.

The isolated test executes six functions extracted from current source, with fake clients and declared dependency inputs. It does not import application clients, call a model or write to Supabase. Literal outcomes include:

text
successful_retry_control: campaign_count=1 membership_count_after_retry=1
failure_then_retry: campaign_count=1 membership_count_after_retry=0
previously_unlinked_product_still_derived: products_to_add=1 products_added=1
derived_company_role_upsert: partner -> customer
derived_company_role_upsert: creative_agency -> customer

The unlink case supplies the state after removal and unchanged member evidence; it does not execute the removal or the real evidence readers. Company role replacement occurs in the backfill writer; the separate graph synchronization reports existing role mismatches without applying them. This distinction is essential when deciding the repair boundary.

The live selected catalog confirms enabled row-level security on the four queried tables and records grants, but that alone does not establish effective permission behavior. The campaign-company foreign key has default NO ACTION; the other returned campaign-dependent foreign keys have cascade deletion. The parent-delete route's comment claims company links cascade too. No deletion was executed, and no permission acceptance is claimed.

Repair contract outline — not yet implementation authorization ​

  1. Correction and evidence ownership. Preserve accepted relationships, their supporting evidence, explicit rejections and human edits through synthesis, synchronization, backfills, seeds and generic administration. A removed row alone cannot encode why it disappeared. Trace existing correction storage before choosing a physical design.
  2. Reliable graph writes. A successful campaign operation must leave the intended graph complete, or retain a recoverable incomplete state. Test failures between each write, retries, concurrency and later evidence. Keep existing identifiers and readable old records during rollout.
  3. Participation and contribution. Separate a company's involvement from each credited contribution to a campaign, piece or interval. Inspect the wider credit model before choosing role-aware uniqueness or new storage. Do not widen a key without updating all upsert conflicts and readers.
  4. Incremental recognition. Evaluate new and existing candidate relationships, attach evidence and respect corrections. Manual APIs and fixed seeds are not a substitute for this workflow. Add it only after the preceding contracts and existing activation gates are satisfied.
  5. Consumers and lifecycle. Display every applicable relationship or an explicitly chosen leading one. Define archive, withdrawal and deletion behavior before changing constraints. Verify saved references, permissions, missing media and the original later-vendor walkthrough.

Retaining and hardening the current identities is the starting recommendation. Consolidating write semantics can simplify the system. Selective replacement of a conflicting participation structure remains an option after its consumers and wider credit model are checked; these findings do not justify a wholesale rewrite. Final repair units still require migration/backfill details, compatibility tests, rollback evidence and the approved release boundary.

The bounded independent challenge reran the fixture and compared the raw and parsed catalog receipts, finding no HIGH or MED issue in this evidence unit. That is not resolution of the HIGH-priority system findings. Those repairs, deployed verification and the rest of the program audit remain open.

Credits and event occurrences ​

The selected live event catalog and profiles are in event-continuation-catalog.json; original approvals, exact source passages and the bounded consumer search are in event-credit-trace.json. Both sit under docs/reference/2026-10/2026-10-05/. The earlier credit-continuation-* receipts remain the source for the canonical/legacy credit comparison.

The current event catalog contains 1,450 calendar entries, 16 occurrences, 10 participation rows, one campaign-event link and nine content-event links. These are inventory observations, not verified real-world coverage. Eight occurrences have no calendar link; zero participation rows link to content. The sample names include several annual Air Max Day occurrences without calendar links. Names alone do not establish the correct repair.

campaign_events.event_id references event_instances; content_events.event_id references events_observances. Both junctions have only their two identifiers and created_at. Evidence may live elsewhere, so this does not establish the absence of all supporting evidence. It does mean a repair must specify where relationship evidence and correction ownership live.

The live match_event_by_similarity routine queries the calendar table. The local _insert_events writer submits only name and threshold, then upserts the returned calendar identifier. event-grain-reproduction.py/json executes that actual function with a fake matcher and a pair-key store. Its control writes one relation. Two supplied occurrences sharing a name also produce one relation and increment the counter twice. The supplied year and role are deliberate extra fixture fields, not a claim about the effective analyzer schema. This demonstrates the writer's boundary; it does not reproduce a production misclassification.

The original RM-1 approval explicitly separates dated occurrences and deferred content-event work. RM-2 and the later sponsorship ruling separate participation from per-piece credits and disclosed sponsorship. These findings do not reopen those meanings. Administrative occurrence and participation routes exist; their presence is not evidence of automatic extraction, correct recurrence or accepted user journeys.

The live public routine search found three further legacy credit readers: team_award_velocity, person_award_trajectory and cross_team_collaboration_signals. Their definitions and local endpoint calls are banked in event-credit-extra-catalog.json and the trace. No non-internal trigger was found on the two selected credit tables. This literal public-function search does not exclude dynamic identifiers, other schemas, generic administration or historical imports.

The selected deployed-file parity attempt is in credit-event-deployed-parity.json:

text
exit_code: 255
root@137.184.152.67: Permission denied (publickey).

It performed no backend mutation. Consequently, this unit establishes local source and live catalog evidence, not running-process parity. Effective permissions, query plans, canonical credit writers and the complete vendor/person/event journey remain open. The read-only audit can continue independently of SSH access.

The engineering starting point is to retain and harden the distinct relationships, simplify duplicate write/read contracts, and selectively repair the content-event and legacy-credit boundaries. No production schema, prompt, classification, automation or frontend expansion is authorized by this report. The existing inventory records this as partial coverage, with implementation and acceptance assessments unchanged.

Creative captures and vendor material ​

The selected live structure, page-reference profile and exact writer/reader passages are banked in creative-evidence-selected-catalog.json, creative-page-reference-profile.json and creative-evidence-paths.json under docs/reference/2026-10/2026-10-05/. The isolated creative-page-membership-reproduction.py/json executes the inspected storage functions with a fake unique-URL store. Its different-image control produces four rows and two memberships; a shared image produces three rows and one membership. Text-envelope media references are outside that fixture and can preserve the second reference. The live profile counts 1,612 matching reference occurrences with differing clusters, not 1,612 unique missing assets or verified interface failures.

The repeat-capture and vendor continuation is in capture-vendor-catalog.json, capture-vendor-trace.json and capture-vendor-reproduction.py/json. The fixture extracts the actual local landing and vendor run functions, adoption writer, insert helper, result normalizer and text-body reader. Extraction, storage and events use explicit fakes; it performs no external access, uploads, model calls, database writes or scheduler activation. It does not execute database triggers or the complete analysis endpoint.

Literal outcomes:

text
landing_new: calls=[extract,store], new_after_dedup=1
landing_existing_changed: calls=[extract], new_after_dedup=0
vendor_new: insert_count=1, stored_copy="new copy", analyzer_input=""
vendor_existing_changed: stored_copy="new copy", analyzer_input="old text envelope"
vendor_existing_changed: stored_analysis={summary:"old analysis"}
vendor_existing_changed: normalized_inserted_count=0, normalized_has_adopted_ids=false

The landing fixture supplies a changed body hash; the actual run skips storage by existing canonical URL after extraction. This is not a claim about every monitoring entrypoint. For a new vendor text row, the actual insert helper retains the supplied copy_text but does not populate text_content; the inspected analyzer reads only the latter and rejects an empty body. For an existing row, the fixture deliberately supplies old text and analysis. Adoption updates its copy and scrape metadata without changing those fields. These demonstrate local contract mismatches, not a fresh production failure.

The result normalizer drops adopted_cids; an existing dispatcher test explicitly expects that behavior. The inspected scheduler's text hook considers only inserted_cids and skips rows with existing analysis. A repair must therefore define changed-item processing across the writer, normalized result, scheduler, analyzer and readers. Simply adding a fallback field or forcing all analysis would leave evidence versioning and human corrections unresolved.

The read-only vendor profile finds 21 rows from one DevDay case-study URL, 19 active. All 19 active rows have campaign links and credits; the 19 credit records carry the earlier controlled-import source. The single vendor source link is inactive with no recorded collection count. These observations do not prove an autonomous recognition or reanalysis process. Existing adoption candidates are selected within the same page; cross-source creative identity is not demonstrated by that matching logic.

Repair boundaries and remaining evidence ​

Retain stable creative identifiers while representing each appearance and dated capture explicitly. Before choosing storage, trace the existing snapshot and placement consumers and determine how independently useful parts refer to their original document or physical work. New and changed captures need a shared analyzable input contract, explicit processing outcomes and evidence-aware invalidation that preserves human corrections. Later vendor material must connect to existing campaigns and credited contributions through supported evidence, not source ownership alone.

The bounded recommendation is to harden these contracts and simplify inconsistent processing inputs. Selective replacement of page membership storage remains an architecture option after compatibility and query behavior are evaluated. No new physical schema is selected here. Final repair units must cover duplicate URLs, changed bodies, shared assets, retry/concurrency, withdrawals, capture history, saved references, access and rollback. Deployed parity, database-trigger effects and complete end-to-end acceptance remain unverified. The next coverage area is shared vocabulary and page context; these limitations remain visible rather than restarting this investigation indefinitely.

Concept writers and review ​

The selected vocabulary continuation is in vocabulary-continuation-{catalog,trace,checks}.json and vocabulary-generator-reproduction.json under docs/reference/2026-10/2026-10-05/. It distinguishes the missing Concepts explanation from the specific creative-device vocabulary. All-row craft hierarchy checks found no parent cycles, missing parents or level-step mismatches. Nonempty definitions do not establish semantic correctness. The actual generator reproduces Animation's list of seventeen children, including fourteen inactive entries whose source and built pages are absent. Hosted target behavior and the complete vocabulary remain unverified.

concept-writer-{catalog,profile,trace,checks}.json, concept-function-consumers.json and concept-writer-reproduction.py/json extend the trace to selected writers and readers. Live checks on 6 October show 2,629 moment concept rows, including 2,569 unregistered rows; none are marked for review. The 303 whole-piece rows include thirty unregistered rows, nineteen marked. All sampled-table rows have analyzer provenance. These are row counts, not distinct-word counts, proof of incorrect meanings or historical writer attribution.

The selected scene prompt permits open concept descriptions. Its normalization does not consult the concept registry, and its junction writer omits the review flag. The live default is false; no non-internal trigger exists on this table. The review routine selects flagged rows only. The Next.js admin queue reads that routine directly and overlays snoozed/reviewed state; the similarly named backend route is a separate implementation. That distinction prevents a misleading frontend-to-backend trace.

The isolated fixture executes the actual local functions with a fake store reflecting the probed unique keys:

text
same_human_value: provenance human -> analyzer
different_human_value: human row preserved
empty_analyzer_result: earlier analyzer row retained
write_failure_after_delete: rows=[]; error recorded
unknown_whole_piece_value: needs_taxonomy_review=true
unknown_moment_value: needs_taxonomy_review=false
moment_human_collision: human row retained; prior analyzer row removed; writer returns None
alias_refresh_same_process: old map retained; select_calls=1

Whole-piece uniqueness uses content_id,concept; moment uniqueness uses segment_id,concept. Neither includes provenance. The whole-piece writer removes only analyzer rows, but then upserts on the whole-piece key. The PostgreSQL 17 INSERT documentation explains why a conflicting upsert updates the existing row. The moment writer instead inserts, catches the unique collision and logs it. These are selected contract hazards; the fixture is not a real PostgreSQL, API, permission or deployed-backend test.

The whole-piece facet joins through content_id, while moment records use segment_id. Finding a parent through a matching moment requires an explicit query path that preserves the match explanation. Other search surfaces remain to trace. The alias fixture verifies process-local caching only; it does not complete the mutation/invalidation audit.

Repair boundary ​

Preserve human decisions and evidence, distinguish a valid empty result from failed or missing input, and make replacement recoverable. Apply the approved candidate-review rules at each subject scope; preserve useful unfamiliar descriptions without silently promoting or deleting them. Trace effective prompts, aliases, review state, filters and saved evidence together before selecting migrations or backfills. Test same-value and different-value human rows, concurrency, retries, partial failure, withdrawal and rollback. The independent challenge matched the bounded reproduction without evidence-overclaim findings; the high-priority system risks remain unresolved. No production repair, broad reanalysis or automation activation occurred.

Audience contracts ​

The previous continuation's receipts are audience-selected-{catalog,profile}.json, vocabulary-definition-profile.json, audience-definition-trace.json, audience-consumer-locations.txt and audience-definition-checks.json under docs/reference/2026-10/2026-10-05/. The trace preserves 23 exact passages. It distinguishes the approved multi-audience requirement from the separate prose describing an intended response.

The selected admin registry binds the prose goal field to a five-value enum editor. The inspected PATCH path permits that field; the analyzer accepts nonempty prose. The generated reference's claim that nothing writes the enum and that it is unrelated to the prose is therefore too broad. The 6 October profile found 9,058 nonempty goals and zero exact matches to those five values. That does not prove historical nonuse, an exercised admin write or production loss. Selected synthesis wording also calls the goal a funnel stage; no resulting model error was demonstrated.

The content-audience junction contains 21,249 analyzer rows across 8,933 pieces; 6,941 pieces have multiple audiences. The selected query path reads the junction. That establishes storage and a query mechanism, not the full cross-company/product/feature research journey. The writer shares the separately identified delete/upsert preservation risks; no new production-write experiment was run.

Across 973 active nondeleted registry values, 582 lack descriptions, 939 lack inclusion rules and 933 lack exclusion rules. These are field-presence aggregates, not semantic judgments or a requirement that every entry needs every field. They do not reproduce the renderer's internal-note detection. All 95 active craft entries have those three fields populated, but their correctness remains to review. No vocabulary approval, retirement or inheritance rule is inferred.

Page context and source eligibility ​

Unit180 receipts in the same folder are page-context-{catalog,contracts,prompt,profile,schedule,cursor-profile,trace}.json and page-context-reproduction.py/json. Catalog queries preceded field-specific profiles. The trace preserves twenty exact passages. All 24 source-file hashes from the earlier graphics-path receipt still match, allowing reuse of its bounded findings without repeating model runs or presenting older observations as fresh layout inspections.

The current production-marked route.website prompt describes a single product page as product and a family hub as product_group; the local URL classifier distinguishes /products as product and /products/widget as product_detail. The selected backfill gives a recognizable URL precedence over analyzer output. Its URL branch fills a source link only when its page type is absent; its content-derived branch returns early when the content value already matches, without reconciling a differing source link. The fixture executes these exact functions with fake storage:

text
url_overrides_analyzer: content=product_detail link=feature
non_url_reanalysis: content=product link=product tier=low
equal_content_skips_link: content=product link=feature
accepted_empty_cursor: selected=[]
nonempty_cursor_control: selected=[ready]
eligible_after_100_inactive: selected=[]

The fixture does not simulate PostgreSQL triggers, deployed runtime, permissions or UI writes. It uses constructed URLs and states to expose code precedence; these are not claims about specific historical pages. The backfill does not directly rewrite the source link's tier or channel. A retained tier may be an intentional override, so a mismatch with defaults is not automatically a defect. Live channel derivation prefers a linked source's channel; the content trigger invokes that function on relevant content updates and can change the content channel. No corresponding link-to-content channel propagation trigger appeared in the selected trigger inventory. Other writers remain to inspect.

The local admin accept endpoint seeds adapter_config.s310b_cursor with an empty object when absent. The scheduler's selected-link function instead checks cursor truthiness. Its nonempty control passes and its empty-object case is excluded. On 6 October the live aggregate found 937 active, undeleted website links with an empty object; three further active website links have no cursor. This does not establish deployed parity, which entrypoint collected them historically, or missed runs. The existing master activation gate remains untouched.

The separate limit-before-filter behavior was already documented in the September pilot RESULTS. This unit reuses that finding and reproduces the current function with ordered fake rows; it does not claim measured production starvation. The pending-source display also has outdated fallback tiers for several page types compared with the current database defaults. All website links in the selected live profile have stored tiers, and the accept endpoint does not send the fallback tier. Thus the verified issue is a divergent fallback/display contract, not a demonstrated bad schedule write.

The live scheduling trigger derives next_collection_at from collection_frequency when active, while the local tier-aware scheduler has a separate flag and tier mapping. Their complete execution order, effective deployment settings and other scheduler entrypoints remain open. This unit did not run either schedule or change settings.

Contract direction and next coverage ​

Retain and harden the approved distinctions: whole page, captured layout, section role, contained element, reusable asset and each appearance. Replace unsupported certainty from extraction hints with explicit evidence and uncertainty. Preserve compatibility for section_detail and msft_records until all readers are traced. Reconcile older blanket inheritance prose with the approved requirement for evidence of each depicted subject or appearance; parent context alone is not per-asset proof.

Separate descriptive classification from operator scheduling policy. A repair must cover source approval, eligibility, fair selection, page/source update precedence, human corrections, changed captures, processing outcomes and readers. Test deliberate schedule overrides, empty and initialized cursors, sources outside the first batch, changed labels, shared assets, retry, partial failure and rollback. Reuse the earlier capture/vendor and correction-preservation contracts. No new physical model is selected, no automated source is activated, and no production schema, prompt, data or API is changed by this audit.

Effective prompt provenance ​

Unit181 evidence in docs/reference/2026-10/2026-10-05/ includes effective-prompt-provenance-{catalog,profile}.json, effective-prompt-alternate-stores.json, effective-prompt-trace.json and effective-prompt-reproduction.py/json. The preceding continuation's route/version/index profiles and binding function remain separately dated evidence. The current trace preserves 21 exact source passages. This is bounded composition and observability coverage, not the complete workflow audit.

Text uses the source/category resolver's stored prompt and schema where present. Image and video use route system instructions, but their user templates and structural envelopes come from code. Cluster-image analysis supplies its own system and constructed user instructions; its route lookup occurs afterward for logging. The frame-preparation classifier also calls a separate binding resolver. These paths must not be conflated into one routing claim. The current Revised Pipeline prose still says stored schema wins generally and its format table describes outdated overrides; this conflicts with the inspected code. No deployed parity is claimed.

A read-only aggregate over the four selected pipeline_executions stages found:

StageRowsWith prompt versionWith either stored prompt hashLatest recorded run
analyze2,7682,768021 July 2026
analyze_text3,5763,54106 July 2026
analyze_image3,5243,494020 July 2026
analyze_cluster_images916913022 June 2026

The shared terminal logger does not submit either hash field; no non-internal trigger exists on this selected log table. The inspected admin hook reads this table directly. These facts do not exclude other stores. The catalog confirms analysis_run has Langfuse and prompt references and analysis_output stores results/metrics. The Gemini client has optional trace spans with shortened prompt text, but the selected analyzer calls do not supply a trace argument. External Langfuse history, alternate analysis writers and complete historical reconstruction remain unverified.

The isolated reproduction executes actual REST request functions and the shared logger with fake HTTP/database objects. It loads the actual JSON-schema converter and separately evaluates the actual text-route logging predicate:

text
text_valid: responseSchema sent=true; text logging predicate=true
text_invalid: responseSchema sent=false; text logging predicate=true
text_converter_exception: responseSchema sent=false; text logging predicate=true
media_valid: responseSchema sent=true
media_invalid: responseSchema sent=false
media_converter_exception: responseSchema sent=false
terminal_logger: system_prompt_hash absent; user_prompt_hash absent
network_calls:0 database_writes:0

The invalid input deliberately supplies an array field without its required item definition. The exception case injects a converter failure. Both request functions continue with JSON MIME type but without responseSchema; the text logging predicate only checks for a dictionary of document fields. The fixture does not run the entire analyzer, model, permission path or deployed process, and it does not establish that such input was used historically. The image logger separately writes schema_enforced=true; full fallback/retry attribution still needs review.

Repair boundary ​

Retain the existing route intent while giving each execution a reproducible, format-aware analysis record: effective prompt/schema identity, code and vocabulary versions, input evidence identity and actual enforcement/fallback outcome. Compare a shared composition contract against retaining format-specific builders with a common record. Do not force every modality into one template merely to simplify logging. Trace all writers, test-prompt tools, retry/fallback paths, model configuration and readers before choosing storage or migrations. Preserve compatibility, corrections and unavailable/private evidence, and specify retention and rollback. This audit performs no prompt change, reanalysis, schema mutation or activation. The full prompt and workflow coverage remains open.

Collection access and saved references ​

Unit183 continues the earlier access finding; it is not a new whole-system assessment. Receipts under docs/reference/2026-10/2026-10-05/ are collection-access-{catalog,role-counts,head-controls,trace}.json, the consumer search and collection-access-reproduction.cjs/json. The preceding lifecycle-* receipts retain the base-table, view, board and segment observations. September's architecture report already identified broad anonymous access; this work confirms selected present behavior and traces its product consequences.

The canonical query contract distinguishes UI Boards, stored in trackers and tracker_items, from UI Trackers, stored as queries in saved_searches. These legacy names must not turn a table-level finding into the wrong user-facing claim. No rename is proposed.

Read-only transactions used SET LOCAL ROLE anon and rollback. Their selected counts on 6 October were:

text
private saved_searches:20; private saved_searches with public_slug:0
private content_markers:1
memberships in private trackers:72; memberships in private reels:0

Independent public-anon-key HEAD requests confirmed HTTP200 and counts20/1 for private saved searches and markers. They retrieved no bodies and used no user session or service-role key. The preceding unit independently confirmed private boards and soft-deleted base content through the same count-only method. Zero private reel memberships is not proof that the reel policy is safe. No mutation exploit, storage request or private content inspection was performed.

The selected catalogs show permissive SELECT policies and grants. Merely enabling row-level security does not establish isolation. PostgreSQL documents how applicable permissive policies combine and how a view's security-invoker option changes whose permissions apply. The existing content view filters deleted rows, but direct base-table access remains a separate boundary. Full view/function/grant dependency closure is still required.

The isolated fixture transpiles and runs four actual local TypeScript routes with explicit fake authentication, database and response objects. Eight cases reproduce:

text
clone_other_owner_private_board:200; source_parent_queried:false; copied_items:1
clone_unauthenticated_control:401; writes:0
share_saved_search:200; is_private_after:true; slug_set:true
shared_private_saved_search_read:200
same_saved_search_public_discovery:200; collections:0
unshared_search_control:404
share_other_owner_control:404; writes:0
private_board_share_read_control:404
network_calls:0; real_database_writes:0

The clone route uses the privileged client to read source membership without checking source-parent access. Its authenticated control is not an ownership check. The saved-search share route checks ownership, then changes only the slug; the public share reader accepts that slug, while public discovery additionally requires is_private=false. The fixture establishes a local contract inconsistency, not actual private-with-slug rows or historical disclosure through this endpoint. Link-only sharing could be intentional, but an unlisted-access policy must be recovered or decided explicitly rather than inferred from code divergence.

Owner hooks for boards and saved searches currently read through the public Supabase singleton with a client-supplied user filter. A selected search finds an authenticated-client helper and server-data helpers, but no callers of those named helpers in frontend/src. This does not establish the absence of every other authentication path. Tightening anonymous access without integrating authorized owner reads could break existing functionality. Supabase's WorkOS integration documentation describes a supported token-based integration option; project configuration, issuer, claims and live session behavior have not been verified here.

Proposed repair contract and acceptance boundary ​

  1. Preserve existing identity and sharing intent. Separate authentication, ownership, explicit sharing, public discovery and access to referenced evidence. Recover whether link-only sharing is an approved policy before changing flag meaning. Do not infer permission from a known identifier, project reference or paid status.
  2. Make the full read path enforce that intent. Cover direct tables/views/functions, owner hooks, server helpers, board copying, share/discovery readers, item membership, annotations and evidence retrieval. Privileged server clients must perform subject-level authorization. Database enforcement must remain effective for ordinary clients.
  3. Retain safe research continuity. Check the parent collection, each child reference and private annotations independently. Preserve ordering and recoverable references when targets are withdrawn or unavailable; return a truthful unavailable state without leaking protected metadata. Ask and citations must use the same authorized evidence set.
  4. Compare bounded approaches. Retain and harden the current identities with consistent policies; simplify ordinary collection reads through authenticated server contracts; or selectively integrate verified WorkOS tokens with database policies for direct owner reads. The choice requires the complete consumer and session trace. A blanket permission removal or a frontend-only filter is not a complete repair.
  5. Verify compatibility and failure behavior before rollout. Test anonymous, owner, other-user, revoked collaborator and operator roles; private source copying; a public collection referencing private annotations; deleted and restored targets; account switching and caches; direct API, function and view access. Include negative controls and equivalent owner/public query results where authorized.
  6. Specify release and rollback together. Stage authorized-reader compatibility and policy changes in dependency order, record existing grants and rules, and verify both denied access and valid owner journeys. A failed rollout must fail closed; reopening broad anonymous access is not an acceptable recovery strategy. Migrations and repairs require separate approval.

Remaining coverage includes actual WorkOS/Supabase integration, deployed route and middleware behavior, all collection writers/readers, database functions, target-media access, lifecycle failure handling and complete saved-reference/Ask journeys. No production schema, API, prompt, classification or automation changes occurred. These HIGH-priority system findings remain open even if the evidence checks pass.

Saved-reference lifecycle continuation — 6 October ​

Unit184 receipts are saved-reference-{catalog,profile,trace}.json, the selected consumer search and saved-reference-reproduction.cjs/json in the same dated evidence folder. The fresh profile returns aggregates only:

text
board content/render references:302; missing base:0; soft-deleted:0; unpublished present:3
reel references:2; missing base:0; soft-deleted:0; unpublished present:0; no marker:0
public reels with share slug linked to private markers:0

The board count excludes event/comparison references. It is not a semantic or permission assessment of every saved item. Text references are compared to base identifiers as text; no unsafe UUID cast is used. The selected catalog has no foreign key from tracker_items.item_id or reel_items.content_id to content. Their marker foreign keys use ON DELETE SET NULL; a marker's content foreign key uses ON DELETE CASCADE. These constraints do not establish all application deletion behavior. No deletion was run.

The isolated fixture executes two actual route files and source-extracted useMemo callbacks from the board and shared-reel readers. It returns six cases:

text
board_unresolved_reference:input2 displayed1 input_preserved=true
reel_unresolved_content_or_marker:input3 displayed1 input_preserved=true
public_reel_returns_constructed_private_marker:200 annotation_returned=true target_content_queried=false
private_reel_parent_control:404
marker_list_returns_other_owner_private_marker:200 returned1 filters=content_id only
marker_missing_content_control:400
network_calls:0 database_writes:0

The projections retain the available control and omit unresolved targets. A missing lookup cannot itself distinguish withdrawal, deletion, publication filtering, denied access or loading/failure. The shared batch hook reads the filtered content view and normally requires publication; boards explicitly include unpublished work. The three unpublished board targets are therefore not automatically broken references. These are callback tests, not rendered React or actual-phone acceptance.

The public reel route checks its parent but returns the privileged nested marker result without a marker-audience or target-content check. Its constructed nested fixture represents a private annotation; the live aggregate found no such public-reel link. The marker list similarly filters only by content identifier. Middleware requires sign-in for that endpoint; the test does not claim anonymous access through it. The separate marker deletion route checks ownership before hard deletion. Combined with the observed constraints and selected projection, removal can retain the membership row while clearing the clip anchor and omitting it from the displayed clip list. No end-to-end deletion or historical loss is claimed.

A separate attribution mismatch is also recorded: both inspected readers request profiles.display_name, absent from the live catalog. The fixture models that query error; the selected readers continue with null/Unknown attribution. Marker updated_at does exist: an earlier unverified suspicion about its absence was rejected by the catalog.

Contract addition: permission and lifecycle outcomes must travel with a stable saved reference. Distinguish unavailable, forbidden, pending and failed resolution; retain only metadata the viewer may see. Preserve collection order and an explainable anchor state after deletion or withdrawal. Sharing the parent cannot publish private annotations implicitly. Before changing deletion or retention rules, trace every marker writer, saved-item consumer, notification recipient, Ask/citation reader and purge path. Compare hardening current reference resolution with a shared authorized resolver; do not hide the problem with a fallback to unfiltered base content. The existing access repair boundary remains the owner of this work. Full auth integration, deployed parity, media authorization, cache/session behavior and deletion/restore failure coverage remain open. No production repair or new retention policy is selected.

Deletion, restoration and marker failure outcomes ​

Unit185 adds lifecycle-failure-reproduction.py/json, marker-failure-reproduction.cjs/json and lifecycle-failure-trace.json. It completes the selected failure experiments identified in the previous continuation, not the wider lifecycle or access audit.

The Python fixture extracts the actual shared fetch, soft-delete and restore functions into an isolated module. It supplies fake database responses, a fake audit emitter and an HTTP-exception stub. Ten cases establish:

text
delete_success / restore_success:success=true audit1 updated1
delete_audit_failure / restore_audit_failure:500 audit0 updated0; no update attempted
delete_update_failure / restore_update_failure:500 audit1 updated0
delete_read_failure / delete_missing_control:404 audit0 updated0
delete_zero_affected / restore_zero_affected:success=true audit1 updated0

Both successful controls record audit before update. The zero-affected cases return an empty update response after an earlier successful read; they model a possible interleaving without exercising a real PostgreSQL race. The helper ignores that response and returns success. A read exception is logged and converted to the same missing-row result as a genuine absence. The content restore route delegates to this helper; the consumer search also locates other selected admin callers. Other mutation helpers and deployed routes have not been certified by this fixture.

Audit success followed by update failure is already explicitly documented in DATA-INTEGRITY.md section5.1.1. This test rechecks that local behavior; it does not discover or approve the old design anew. The fake emitter does not verify live audit serialization, grants, constraints or reconciliation jobs. No real deletion or restoration occurred.

The TypeScript fixture executes the actual marker hooks with captured React-hook options and the installed TanStack QueryClient/MutationObserver (5.90.20). It fakes only HTTP and invalidation I/O. Eight cases establish:

text
list HTTP500:query success, [] — same result as HTTP200 empty control
list network exception:query error
create HTTP500 / update HTTP403:mutation success, null, one invalidation
create HTTP200 control:mutation success, marker returned, one invalidation
delete HTTP500:mutation success, undefined, one invalidation
delete network exception:mutation error, no invalidation

The non-OK HTTP branches fulfill rather than reject; network exceptions remain errors. This is query/mutation state evidence, not a rendered success toast or deployed user-session test. An initial assertion compared arrays from separate VM realms and failed on prototype identity; it was corrected to compare serialized values without changing the application or expected outcomes. All eighteen cases run without network calls or database writes.

Repair addition: use a shared, explicit operation outcome across server mutation, audit and client state. Confirm the intended row transition before reporting completion; distinguish absence, permission denial, conflict and infrastructure failure. Preserve drafts and saved ordering on failure. Retain the fail-closed audit requirement. Compare a transactionally coupled transition/audit operation with an explicit attempt-and-outcome design, including all existing callers and historical audit readers, before selecting a repair. Verify zero-affected updates, concurrent state changes, audit failure, mutation failure, retries and restore visibility. A stronger error message alone cannot repair an unconfirmed state transition. Cache/session behavior, target-media permissions, purge/retention execution and complete end-to-end acceptance remain open. No production schema, runtime behavior, API, prompt, classification or automation was changed.

Structural coverage across the public catalog ​

Unit186 returns from selected lifecycle tests to whole-catalog coverage. Three read-only receipts, structural-coverage-{catalog,detail,routines}.json, preserve SQL, timestamps, literal responses and parsed rows. structural-coverage-check.py projects them into structural-coverage-assessment.json; this is evidence beneath the existing inventory, not a second queue. No production object or data was changed.

text
relations198: tables184 views13 materialized_view1
attributes2299; information_schema_columns2296
indexes598; invalid/unready/not-live0; unvalidated_constraints0
foreign_keys200: unconditional_prefix142 nonnull_prefix45 review_candidates13
tables_without_primary_key50
routines268: extension_owned190 nonextension78
nonextension_definitions_captured78; selected_catalog_dependency_edges984
screening_controls8

All 200 foreign keys in this receipt have one source column. The three additional attributes belong to mv_facet_counts; information_schema does not include that materialized view here. Nonextension routines are the next application-review set, not proof that all 78 are active consumers. Extension-owned routines remain dependencies in scope.

The index screen requires a valid, ready B-tree with the FK column first among its key columns. It separately recognizes the exact single-column IS NOT NULL predicate. It does not certify planner use or measured performance. Eight controls include invalid, unready, nonleading-key, alternative-method, unrelated-predicate and included-column-only rejection. PostgreSQL's partial-index guidance requires the query to imply the predicate; matching a column name alone is insufficient.

The thirteen remaining candidates are:

TableReferencing columns needing query/lifecycle review
campaign_intelligence_evidence_refscampaign_id, scene_id, source_evidence_id
comment_read_statethread_id
content_creditdiscipline_id, person_id, run_id
entity_ownershipowned_entity_id; its leading index covers active rows only
pending_entity_peopleproposed_department_id, reviewed_by
productsbrand_entity_id; its leading index covers products operating as brands only
sectorsmacro_sector_id
taxonomy_aliascanonical_enum_id

These are candidates, not confirmed slow queries or required migrations. For example, the inspected ownership reader asks for both relationship directions without restricting active status. By contrast, the comment reader also filters by user, so an index useful for its normal read can differ from one useful for parent deletion. Trace actual predicates, join cardinality, data size, statistics and deletion behavior before recommending indexes. No unused index is proposed for removal.

The 50 tables without primary keys all have names suggesting archival or snapshot use. The assessment preserves every name and leaves retention, ownership and consumers unverified; it does not authorize deletion or treat naming as lifecycle evidence.

Catalog dependencies cover selected public routines, view rules and noninternal triggers. They are not transitive application dependency closure. PostgreSQL does not record body-only dependencies for string-defined routines. Source-body and caller tracing remain necessary, particularly for dynamic SQL. Full routine execution, role behavior, query plans, semantic data profiles, remaining workflow entrypoints and deployed parity stay open.

The bounded independent challenge reproduced the assessment, compared all three literal/parsed receipts, checked 187 accepted index-column matches and reran the eight controls without HIGH/MED evidence issues. Root separately checked raw/parsed equality and the single-column scope. Underlying system findings and unexamined coverage remain open. The next work is routine/caller and query-path review in dependency order, not another isolated naming packet or a blanket schema rewrite.

Hierarchy maintenance and section meaning ​

Unit187 follows the previous routine inventory. hierarchy-routine-{catalog,types,profile,trace}.json preserve fresh read-only responses, exact local passages and search scope. hierarchy-routine-reproduction.py/json recreate selected live column types, defaults, nullability, constraints, functions and triggers in a temporary local PostgreSQL database. The server listens only on a temporary Unix socket and is stopped afterward. No application records or credentials are loaded.

The 6 October profile covers all entity rows, including deleted or inactive entries. All 2,438 are reachable from roots; maximum depth is three, null levels and stored-depth mismatches are zero. The current section closure contains 110 rows and exactly matches independently calculated ancestry: zero missing or extra triples. These are structural observations, not semantic validation of every relationship or proof of writer safety.

Reproduced maintenance gaps ​

text
valid_entity_chain: depths 0,1,2
direct_self_parent_rejected: entity_no_self_parent constraint
same_depth_reparent_control: descendant level remains2
descendant_level_stale_after_reparent: stored2, calculated1
two_node_cycle_stored: both reciprocal edges retained
cycle_descendant_query_timeout: statement timeout after250ms
section_depth_three_control: ancestor link depth3 present
section_depth_four_missing: ancestor link absent

The entity trigger recalculates only the changed row on insertion or an update naming parent_entity_id. The selected constraints reject self-parenting and require an existing parent, but do not prevent longer cycles. Captured ancestor/descendant functions recurse with UNION ALL without visited-node checks. PostgreSQL's recursive-query guidance explains why changing to UNION alone is insufficient when depth changes on each iteration. Reader termination and write-time graph validity need separate guarantees.

The inspected admin PATCH forwards through the backend entity request to update_with_audit, which sends the parent change to the database. Its inspected path has no graph validation. Two pipeline product-creation paths also submit parent links, with source-ownership guards. Those guards answer whether a proposed parent has supporting evidence; they do not replace general hierarchy integrity. The admin hierarchy tab calls get_entity_descendant_tree and constructs a recursive tree from its result. These are source traces, not executed authenticated HTTP journeys or proof of every generic/dynamic writer.

The section-maintenance triggers rebuild the whole closure after insert, delete or a parent update. The captured function writes self, parent, grandparent and great-grandparent links only. The table's independent level check allows zero through six; it neither derives actual depth nor constrains ancestry to three. The isolated five-node chain is accepted but lacks the root-to-last link. Current data stop at depth two and have no closure discrepancy, so this is a tested latent maintenance limitation, not a demonstrated production omission. Concurrent rebuild behavior remains untested.

All 46 current section rows were inspected by name, level and parent. They describe navigation topics such as Business Profile, Company Profile and Finance. The selected code search finds their names in the admin table-category list, but no dedicated writer/reader in the searched application files. Generic administration, database views and external consumers remain possible; absence of a literal match is not proof of nonuse.

MOMENTS-SCHEMA-AND-DATA-CONTRACT.md calls these tables a web-region grain; MOMENTS-PLAN-TASKS.md ties website section/region work to the same table. MOMENTS-PIPELINE-REVISION.md explicitly identifies it as the navigation taxonomy and warns against the conflation. Exact passages are banked in the trace. The approved whole-page, section-role, element and appearance distinctions remain unchanged. Correct these references during the agreed Docs reconciliation; do not reuse a similarly named table without examining its existing semantics and consumers.

Repair boundary and evidence limits ​

Retain the approved distinction between brand structure, corporate ownership and product membership. For true trees, specify atomic cycle-safe moves, deletion behavior, evidence and correction history. Compare maintaining descendant depths transactionally with deriving depth in reads; a one-row trigger cannot maintain a moved subtree alone. For navigation closure, compare complete transactional maintenance with recursive reads after checking actual consumers and query plans. Do not add an arbitrary depth cap to hide an invalid graph. Preserve identifiers, test concurrent moves, rollback and old readers, and keep website-capture repair in its own existing contract.

The fixture runs PostgreSQL14.22, while the earlier hosted catalog reported17.6. It reproduces exact selected routine bodies and table rules, not production permissions, all indexes, every dependency, HTTP behavior or concurrent transactions. Setup initially failed on information-schema type labels and missing statement delimiters; the fixture now uses qualified underlying types, captures the actual enum labels and terminates routine statements explicitly. The eight application-behavior assertions were not weakened. The findings justify scoped repair contracts, not a claim that production data are corrupt. No production schemas, APIs, prompts, stored classifications or automation settings changed. Remaining routine, workflow, permission, definition and deployed-parity coverage stays open.

View access and page selection ​

Unit188 completes a bounded continuation of the fourteen-view inventory. Evidence is in docs/reference/2026-10/2026-10-05/view-access-catalog.json, view-anonymous-counts.json, view-access-http-control.py/json, view-selected-records.json, view-page-grain.json and view-access-selection-trace.json. The preceding view-selection receipts preserve exact definitions, ordering controls and two query plans. The current unit adds permissions, count-only public HTTP controls and the actual page-versus-asset selection path.

Admin-only intent is not enforced by the current view ​

The fresh catalog lists thirteen ordinary public views owned by postgres, all with null view options and SELECT permitted to both anon and authenticated. The materialized view mv_facet_counts denies both roles. A read-only transaction under SET LOCAL ROLE anon returned counts from all thirteen ordinary views. This is measured access, not a conclusion that all thirteen should be private.

20260619113125_qv24_4_admin_discovered_link_review.sql explicitly describes an admin-only read model, sets security_invoker=true, revokes client-role access and grants SELECT to service_role. The current catalog has no invoker option and permits client-role SELECT. That establishes drift from the migration's contract; the historical operation that introduced the drift has not been established.

text
public-key HEAD v_admin_discovered_link_review: HTTP200 Content-Range0-943/944
public-key HEAD persona_routing: HTTP200 Content-Range0-27/28
public-key HEAD mv_facet_counts: HTTP401
response bodies retrieved:false; signed-in session:none; service-role key:none

The local admin-links route calls requireAdmin before using its server database client. That guard cannot protect a separate directly accessible database endpoint. PostgreSQL's view permission rules distinguish owner and invoker checks; Supabase's view guidance explains their RLS consequence. The HTTP controls confirm the selected live access path without retrieving record contents, testing writes or claiming historical disclosure.

The current landing-page builder creates a text record with asset_type=page_copy, plus screenshot, image and video records. It carries the same source type and page link into insert_content_item_stub, which persists each record into content_item. Sharing the source is legitimate provenance; it does not make these records interchangeable.

The live review view selects any undeleted landing_page record matching the link or URL. It prioritizes a direct link, any non-null analysis status and creation time, without requiring a complete-page record. Its relationship aggregates use only that selected content identifier. The local admin API merges that graph onto each source; DiscoveredPages displays its title, companies, products, features, classifications and review state.

text
review rows944; selected content records928
selected text854; image73; video1
nontext selections with an undeleted exact-URL text page available51

The existence of a text alternative does not prove it is analyzed or complete. The literal analysis_status='analyzed' diagnostic returned zero in the receipt; that literal was not validated as the success vocabulary and is not used to claim absence of completed analysis. This finding concerns the identity of the reviewed record, not whether all 74 selections have the same historical cause or correct replacement.

Earlier five constructed ordering controls also show nullable direct-link expressions and null timestamps sorting first under the captured descending order. Current profiles found no mixed direct/null-link candidate groups, null timestamps or ordering ties; those are latent ordering risks, not explanations for the observed 74 asset selections. The populated query-plan sample returned25 rows in64.180ms; it is not a load test or full-interface performance result.

Repair boundary and next coverage ​

Extend the existing access repair to enumerate each view's intended audience, enforce it at the database boundary and preserve authorized server consumers. Test signed-out, permitted and denied roles independently. Compare invoker views with narrowly granted server-only views according to each actual contract; do not blanket-revoke public discovery or assume invoker mode alone defines the product's authorization rules.

Extend the page-context contract to identify the whole-page analysis explicitly and expose extracted-asset analysis separately. Preserve incomplete and missing states, stable selection, evidence and human corrections. Include the landing writer, review view, backfill script, admin API and review columns in compatibility and rollback tests. Do not relabel every asset's source merely to make the current reader work.

This is read-only live evidence plus local source tracing. It does not certify deployed backend parity, authenticated UI execution, every view's semantics, every workflow or full audit completion. No production repair was attempted. The next coverage is remaining workflows, vocabulary and item-level obligation reconciliation rather than reopening this bounded view check without new evidence.

Brand-guideline onboarding, review and recovery ​

Unit191 continues the registered onboarding entrypoint. onboarding-trace.json preserves ten source passages, eight hashes and the scoped consumer search. onboarding-reproduction.py/json execute eleven cases using the actual extracted Python functions and request/response models with fake extraction, model and storage adapters. onboarding-reader-reproduction.cjs/json execute four cases using the actual metadata projection and the identity-page selection callback. They make no network requests or production writes and do not test authentication, React rendering or concurrency.

The earlier onboarding-continuation-catalog/profile.json receipts captured the selected live columns, constraints, triggers and aggregate counts on 6 October. They reported 94 sections across twelve entities, 78 published and sixteen unpublished, with all 94 lacking source_url. A missing URL in this field does not prove absent evidence elsewhere or semantic error. The fresh profile, policy and dependency follow-up returned FgaApiAuthenticationError; onboarding-access-recheck.json retains the failure. It supplies no new database result and does not recertify the earlier observations.

Source and review boundaries ​

structure_brand_guidelines assembles extracted text without its accompanying page URLs. When the text is empty, the user prompt explicitly asks the model to use training knowledge. Discovery and extraction failures can still reach this stage. The response carries generated sections and company metadata into seed_brand_guidelines.

That writer marks new sections is_published=False, but separately merges generated metadata onto the entity. A generated value replaces an existing value with the same key; unrelated keys survive. This is not preservation of an approved human value merely because the operation is called a merge.

The consumer hook asks for published sections. The brand page uses those when present; otherwise it calls metadataToSections. That converter creates synthetic sections marked published, including a mission statement. The fixture passes generated metadata from the writer test into this actual selection path and receives the generated statement despite an empty published-section result. It proves a local review-boundary inconsistency, not that an unauthorized user has accessed a deployed page.

text
existing_no_force: reviewed section and human mission retained
new_draft: unpublished section; source_url null; generated mission replaces same key
empty_source_prompt: training-knowledge instruction present
nonempty_source_prompt: extracted text present; accompanying source URL absent
no_source_route: completed with an unpublished generated section
no_published_sections: generated mission projected as a published synthetic section
published_control: existing published section selected
admin_draft_control: draft selected for admin
empty_metadata_control: no synthetic sections

The source-backed strategy rule is already approved in the Content chapter. It requires preserving actual wording, its source and its subject, with interpretation separate. No further approval of Purpose, Mission, Voice or Values is needed to establish this repair requirement.

Regeneration and lifecycle ​

Forced regeneration hard-deletes all matching sections before the separate insert. The model call occurs first: a failure there preserves existing rows. Once seeding begins, however, an empty section list can delete the old rows and return a completed response. An injected insert failure returns an error after the fake store has lost its old sections.

text
force_success: prior identifier removed; replacement is a draft
force_insert_failure: injected error; remaining sections0
force_empty_result: remaining sections0
empty_regeneration_route: completed; created0; remaining0
failed_regeneration_route: HTTP500; remaining0
structure_failure_control: HTTP500; remaining1

These are fake-storage outcomes. They do not establish that a real deletion succeeds through current permissions and dependent constraints, that production data were lost, or that no external recovery exists. The selected manual edit/removal routes instead use audit-aware update and soft-delete helpers. A separate admin hook publishes directly through Supabase. Their existence makes lifecycle consistency an explicit consumer requirement; it does not certify every helper or current grant.

Repair contract to complete ​

Retain the approved meaning and harden the complete path. Carry source identity and exact statements through extraction, generation, validation and review. Keep unsupported interpretation separate. Review must govern generated company metadata as well as guideline sections; a fallback renderer cannot silently treat an unreviewed value as approved. Preserve legitimate existing metadata behavior through an explicit compatibility rule rather than simply removing the fallback.

Validate and stage a replacement before changing current published work. Compare an atomic replacement that retains durable references with versioned drafts promoted after review. Both alternatives must preserve human corrections, evidence, publication state and recoverability. Include empty output, insert/update failure, retries, concurrent regeneration, manual edits, withdrawal, restoration and old-reader compatibility. The choice of physical storage remains open pending live dependency and permission verification; this audit does not prescribe an unprobed migration.

The bounded independent review reran all fifteen cases and checked hashes and earlier literal/parsed receipts without HIGH/MED evidence issues. Root reran the fixtures and matched outputs, excluding generated reader timestamps. This closes only this selected source-level investigation. Deployed parity, source-provider behavior, authorization, dependency closure, rendered acceptance and the remaining onboarding/monitoring workflows stay open. No production schema, API, prompt, data or automation setting changed.

Scheduler controls, costs and outcomes ​

Unit192 adds scheduler-control-trace.json and scheduler-control-reproduction.py/json beneath docs/reference/2026-10/2026-10-05/. They extend scheduler-gate-continuation.json and scheduler-gate-reproduction.py/json. The new trace contains twelve exact passages, nine file hashes and a scoped consumer search. Both fixtures extract actual Python methods and routes, replacing external dependencies with explicit fakes. The control fixture mirrors only the two source-verified JavaScript state/toggle expressions; it does not execute React or the request proxy. No network call, production write, paid collection or scheduler activation occurs.

Gate and collection failures ​

The recurring loop reads the runtime switch before calling run_cycle. A failed flag query returns false, but a missing row returns true. The task now starts independently of the boot environment setting, so the old comment explaining the missing-row behavior as an environment-gated compatibility fallback is stale. The readiness endpoint also reports a missing row as enabled. These are local-source facts, not a fresh observation of the deployed flag.

The cycle has an explicit spend-probe exception branch, but _fetch_24h_cost catches query errors and returns zero. Similarly, _list_active_links converts query errors into an empty list before the outer cycle can report them. The earlier eight-case fixture was rerun and matched its banked output:

text
flag false:false; true:true; missing:true; read error:false
cost limit control:skipped_cost_floor; handler calls0
cost read failure:completed; spend0; handler calls1
source read failure:completed; attempted0
valid zero-cost control:completed; handler calls1

ADR-055 explicitly requires stopping and alerting when the spend probe fails. Its absence-of-opt-in rule also conflicts with the missing-row behavior. The helper reads at most 5,000 cost rows and sums them in the application. Complete accounting must be verified against actual population, service limits and vendor writers before relying on that total. This audit does not claim measured undercount or overspend. Source eligibility and limit-before-filter findings remain in the earlier page-context unit rather than being counted as new defects here.

The read and write controls disagree ​

SourceScheduler.enabled returns the boot-time environment value. GET /api/admin/scheduler/state exposes that property. The authenticated Next.js proxy forwards its response, and useSchedulerState supplies it to the lab Control and Sources pages. Both label it as the runtime master state; Control computes the requested next state by negating it. Its mutation posts through an authenticated proxy to set_master_enabled, which audits and writes the database runtime flag. The older scheduler page explicitly labels the environment value and is not evidence of the same labeling defect.

text
boot false/runtime true:display false; toggle requests true; runtime remains true; display remains false
boot true/runtime false:display true; toggle requests false; runtime remains false; display remains true

These cases execute the actual state and setter functions with fake storage and mirror the inspected two JavaScript expressions. They demonstrate contract divergence, not a rendered interaction or authenticated deployed request. Invalidating an extra query cannot fix a reader that returns the wrong authority. Unknown/loading/error state must also remain distinct from OFF in the repaired control contract.

Manual execution and history controls ​

The manual route declares super-admin authorization and records audit before calling the cycle. The isolated fixture bypasses framework dependency resolution; it tests route logic, not authorization enforcement. run_cycle does not itself read the master flag. The historical activation checklist distinguishes bounded operator execution from recurring activation, so this fact alone is not an authorization bypass or a reason to prohibit every manual run.

text
audit failure:HTTP500; events[audit]; no cycle
completed control:HTTP200; events[audit,cycle]; summary completed
cost skip:HTTP200; success true; summary skipped_cost_floor
cycle failure:HTTP500; events[audit,cycle]
manual marker cleared after every route case
history success:memory completed; fake durable rows1
history insert failure:memory completed; fake durable rows0; no raised error

An HTTP-success envelope can legitimately carry a skipped summary, but readers must show that outcome. The newer Control summary displays counts and spend without the returned status. The persistence helper logs failure and retains memory state; that is not durable history. Restart/recovery, concurrent manual/scheduled runs, shared attribution state, cancellation and vendor-cost reservations remain untested. No historical lost run or duplicate vendor charge is inferred.

Bounded repair contract and remaining prerequisites ​

Retain and harden the scheduler, simplifying duplicated interpretations of control state. A replacement scheduling framework is not justified by these findings. The repair must cover the loop, manual entrypoint, cost and source helpers, dispatcher outcomes, history persistence, runtime setter/readiness readers, admin proxies, shared hooks and their current consumers.

Require explicit recurring activation; propagate unknown flag, cost and source states without substituting true, zero or empty. Keep authorized manual execution explicit and bounded. Verify the complete spend source and concurrent admission behavior before paid work. Preserve the approved audit-before-action rule while making attempted, skipped, failed, completed and durably recorded outcomes distinguishable. Join these changes to the earlier source-eligibility and changed-capture contracts so safe activation does not merely run an incomplete collection path more often.

Before implementation, recover current live grants, dependencies and runtime settings; verify deployed files; enumerate remaining scheduler and operator entrypoints; and complete the vendor budget, cancellation and concurrency traces. This unit names inspected source references, not newly verified physical schema. No migration is prescribed without a fresh catalog check. Test missing/error/false/true flags, failed and over-budget spend probes, no due sources versus source-query failure, audit failure, persistence failure, retries, restarts and opposite boot/runtime states. Verify valid authorized operation alongside failure controls and every admin reader.

Stage reader compatibility and operation outcomes before activation. Keep recurring automation off during rollout; define rollback that restores a working, fail-closed control contract without silently re-enabling collection. Record exact deployed revision and negative controls before the separately authorized activation gate. The current live database connector remains unavailable from the prior failed attempt; the unauthenticated runtime probe returned HTTP401. Neither establishes current runtime state. This is a bounded local audit and contract outline, not a production repair or completed workflow certification.

Scoped research, conversations and evidence continuity ​

Unit193 connects the retained research-experience requirements to two distinct local analysis paths. Evidence under docs/reference/2026-10/2026-10-05/ includes research-scope-continuation.json, research-consumer-trace.json, and the proxy, platform-function, request-model and chat reproduction scripts/results. The new consumer trace preserves fourteen source hashes and twenty-three exact passages. Earlier workflow-registry entries remain dated leads, not completed workflow certification.

Selection and service boundaries ​

The board route publishes identity-only page context. Its dashboard opens the shared Ask panel, which receives no contentIds from that context. The older board sidebar does pass its resolved content/render members. These are different callers; the finding must not be flattened into “boards never supply content.” An explicit board mention in the chat route also resolves members after checking the parent owner or public flag, with a shared block limit of100. This is not an authorization certification of every referenced item.

The tracker view uses the shared paginated query hook, whose default page size is50. It applies exclusions and text tags to loaded items, displays their count, and passes those identifiers to its analysis sidebar and canvas. The full-file literal search finds no pagination continuation call in this view. These source facts establish a loaded-results boundary, not a measured production omission or proof that a fifty-item limit is always reached. Separate shell chat page context remains identity-only.

The expanded canvas calls the older collection/platform proxies. The actual proxy fixture supplies a signed-in identity and available token, but those callers forward neither token nor request headers. Under a fake backend401, platform analysis attempts a second collection request. Without explicit identifiers, that fallback queries the first200 active items without the requested filters. The backend routes declare JWT protection; its local middleware has disabled, log-only and enforcing modes. No current deployed mode is known, so the fixture does not establish that production requests fail or bypass authorization.

text
proxy collection:401; outbound authorization absent; requests1
proxy platform:401; outbound authorization absent; requests2; fallback IDs unfiltered
proxy signed-out control:401; outbound requests0
explicit-token proxy control: authorization forwarded
platform matching row outside selected limit:404; model calls0
platform date filter: accepted but not applied
platform supplied identifiers: unused by function; discarded by request model
platform duplicate-title answer: both matching records referenced

The platform fixture executes actual extracted functions with fake database/model objects. A separate actual Pydantic-model test confirms that content_ids is not preserved. Its banked runtime was2.12.5; the continuation rerun uses backend-venv2.13.3 and produces the same parsed request. Neither certifies the deployed runtime. Date handling, query equivalence and supported filter names need one explicit contract across browsing, trackers and analysis. Increasing the limit or retrying a different service cannot establish that equivalence.

Chat context, citations and persistence ​

The current Next.js chat route is a separate path. Eight isolated cases transpile and execute it with fake identity, database, model and cost logging:

text
signed_out:401; model calls0
collection_name_without_membership:200; no-content prompt
owned_tracker_mention_is_metadata_only:200; no-content prompt; tracker metadata present
owned_board_resolves_members:200; content context1
other_owner_private_board_excluded:200; generic prompt; no membership query
partial_item_set_not_reported:200; requested2; context1; no coverage field
observation_read_failure_continues:200; model calls1
fifty_records_are_text_context:200; context50; one shared title matches50 references
network calls0; production writes0; paid model calls0

The private-board control excludes the protected membership; it does not return an endpoint denial because generic chat remains available. Tracker mentions being metadata-only is an explicit earlier v1 decision in AI-CHAT-PROMPT.md. That is a capability to extend for the retained research requirement, not an accidental violation of its original contract. The same spec later supersedes its earlier1200 output-token limit with2400; no parameter drift is claimed here.

The selected content path loads stored summaries, observations and published guideline text. Fifty constructed records are not fifty native videos, verified moments or tested answer quality. Observation query errors are ignored through an empty-result fallback. If some requested content is missing, the available subset proceeds without an explicit missing-membership result. Which real records a viewer may read remains part of the unresolved live access review.

Both service and client reference assembly use title substrings. Identical titles therefore produce ambiguous references; the fifty-record fixture deliberately exposes this with a fake answer. It does not measure the frequency of duplicate titles or real model errors. No interval-level or claim-to-evidence citation is demonstrated by this route.

AIAnalysisPanel loads saved messages for display but sends only the new query, current identifiers, label, conversation identifier and mentions. The route converts that query into one user message; the conversation identifier is used for cost telemetry, not history retrieval. ChatThreadView hydrates cited cards but does not pass the original content membership back into the panel. Existing messages and cited identifiers are therefore not a preserved full research scope.

Message read/write routes check conversation ownership. They save answer text, referenced identifiers and scope labels. The caller's saveMessage helper does not inspect HTTP status, so awaiting it does not establish successful persistence. This is a source-level finding, not a reproduced browser loss. The inspected intelligence-session path separately saves filters and counts, while reopening restores answer/query/references against current interface state. These code references do not assert newly verified physical columns or the absence of every alternate snapshot mechanism. Fresh catalog and permission checks remain blocked by the earlier connector failure.

Repair contract and delivery dependency ​

Retain stable collection, conversation and evidence identities. Compare hardening both services under one shared scope contract with consolidating redundant analysis adapters; replace only the conflicting boundary if that makes compatibility provable. The existence of two endpoints alone does not require a rewrite. Preserve deliberate no-content help as a visibly different capability from collection research.

Resolve authorized membership using the same query meaning as browsing, with explicit limits, exclusions and missing/denied outcomes. Record the evidence set actually supplied, its analysis/capture versions, selection rules and coverage with each answer. Preserve that record when a tracker later changes. A fresh follow-up can use either that recorded scope or an explicitly selected current scope; do not silently substitute one for the other. Carry permitted stable piece and moment references through model output, validation, rendering and save/reopen. Title matching cannot serve as citation identity.

Include page-context providers, board/tracker readers, mention resolution, both proxy/backend paths, prompt composition, message/session/note persistence and citation consumers. Integrate with the existing access, correction-preservation and saved-reference repair units. Stage compatible readers before changing writes or retiring a path. Specify migration of legacy saved answers as incomplete historical evidence where full membership cannot be recovered; never invent it. A failed save must remain distinguishable from a durable answer. Rollback must preserve saved work and denied-access behavior.

Acceptance must exercise complete and partial result sets, filters beyond the first page, equal-title records, explicit selections, unavailable/private items, failed observation reads, model failure, failed save, browser reload and tracker change. Verify prior conversation context, query parity, authorized membership and citations to the correct video interval. Run real bounded multi-video retrieval and answer checks only under the existing cost/access gates. Streaming, rendered React behavior, all alternative entrypoints, live grants, deployed parity and complete research acceptance remain open. No production schema, API, prompt, data, automation or frontend behavior changed.

The BrandTrackers domain model. Source: git markdown, drift-checked against the live DB.