diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml
index 9a73249f6..84b953e1a 100644
--- a/.github/workflows/tests.yml
+++ b/.github/workflows/tests.yml
@@ -100,3 +100,11 @@ jobs:
- name: Build Storybook
working-directory: frontend
run: pnpm run build-storybook
+
+ - name: Install Chromium for Storybook browser acceptance
+ working-directory: frontend
+ run: pnpm exec playwright install --with-deps chromium
+
+ - name: Exercise Storybook interactions in Chromium
+ working-directory: frontend
+ run: pnpm run test:storybook:browser
diff --git a/docs/adr/0049-leftover-pair-report-ui.md b/docs/adr/0049-leftover-pair-report-ui.md
index bc59a5026..574388330 100644
--- a/docs/adr/0049-leftover-pair-report-ui.md
+++ b/docs/adr/0049-leftover-pair-report-ui.md
@@ -123,10 +123,22 @@ A hidden post never appears as a leftover pair.
## Consequences
The authorized report payload carries `leftover_pairs` next to
-`members` and `selected_items`. Screen-reader names are
-`Open leftover closest pair: {title}` and
-`Open leftover farthest pair: {title}` so the control announces the
-next action, not only the distance.
+`members` and `selected_items`.
+
+The button's accessible name begins with the **exact localized label that is
+visibly rendered on that button**: `Closest leftover: {title} · {criterion}` or
+`Farthest leftover: {title} · {criterion}`. Localized next-action text follows
+that visible-label prefix, then only formatter-admitted persisted evidence that
+is actually available and finite. Missing or non-finite values are omitted from
+the accessible name; they are never announced as `R —`, `d NaN`, or another
+placeholder. This keeps the programmatic name aligned with the visible label
+required by WCAG 2.2 SC 2.5.3 while still exposing the same buyer evidence to
+screen-reader users. The accessible name does not derive, clamp, repair, or
+synthesize psychometric values.
+
+The historical `Open leftover closest/farthest pair: …` prefix is not the
+screen-reader contract. It may describe the action conceptually, but it must
+not replace the rendered label at the start of the accessible name.
## Related
@@ -136,3 +148,6 @@ coverage of the leftover map is [ADR 0168](0168-leftover-map-complete-case-cover
[ADR 0003](0003-fast-mlsirm-report-integration.md). The grouping
comparison strip reuses this leftover store ([ADR 0149](0149-leftover-pairs-on-comparison-strip.md)).
+
+Accessibility naming follows W3C, *Web Content Accessibility Guidelines (WCAG)
+2.2*, Success Criterion 2.5.3, Label in Name.
diff --git a/docs/evidence/product-technical-gap-baseline-history-through-20260913.md b/docs/evidence/product-technical-gap-baseline-history-through-20260913.md
new file mode 100644
index 000000000..3a2467d15
--- /dev/null
+++ b/docs/evidence/product-technical-gap-baseline-history-through-20260913.md
@@ -0,0 +1,1279 @@
+# Product & Technical Gap Baseline — Historical Snapshot Through 2026-09-13
+
+> Historical evidence only. This snapshot is not current merge or release
+> authority. Use the [current product and technical gap baseline](../product-technical-gap-baseline.md)
+> for live authority.
+>
+> Overlay captured at 2026-09-13 20:27 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified
+> commit signature after two fresh sweeps. No protected-main merge or base movement
+> occurred during this maintenance turn.
+>
+> Customer Master ownership issue #1052 / PR #1055 remains exact
+> `50c4935eef1029467595f7004818643598b737c9`. Repository Tests `34746058653`
+> (including full PostgreSQL), Security `34746058657`, and SAST `34746058639`
+> are terminal GREEN. Required CodeQL `34746058693`, OpenCode `34746057593`,
+> and Noema `34746057619` remain terminal failures at canonical `.github` /
+> contextual-orchestrator owner boundaries. Strix `34746057545` / job
+> `103694153476` remains genuinely `in_progress` at `Run Strix (quick)` on the
+> unchanged head; elapsed time alone is not grounds to cancel it. #1055 therefore
+> remains Ready only to preserve exact-head evidence and is not merge-ready.
+>
+> Fresh catalog-owner review identified buyer-path resilience gap #1077. The
+> canonical `get_or_create_corporate_entity` correctly defers its explicit
+> transaction and `pg_advisory_xact_lock` until after provider work, but existing
+> Keyman/post-summary/Customer Master callers can retain a borrowed asyncpg
+> connection across hierarchy inference/search corroboration. The process pool is
+> bounded at `max_size=10`, so concurrent catalog misses can starve unrelated DB
+> requests without any explicit DB lock. #1077 owns the causal contract: short
+> candidate/alias snapshot lease, release before provider I/O, then a fresh
+> under-lock catalog recheck/write with cancellation/error cleanup. It remains in
+> the corporate-entity catalog bounded context and must not duplicate CO routing.
+>
+> The leftover-map comparison lineage suffix has also converged onto repaired #859.
+> #859 exact `2550e8d88339e30297fa0aa19ffae77f9b78b73b` fixes the eight stale
+> comparison-only distance cases (16 assertions) without changing production or
+> report-mode semantics. The live serialized ancestry is #860 `ef29a5a9...` ->
+> #861 `49973434...` -> #862 `382947ba...` -> #863 `4e8720e9...` -> #865
+> `dec97059...` -> #866 `198d6827...` -> #867 `3e338bc3...` -> #868
+> `8af935c0...` -> #869 `74bd9468...` -> #870 `d063bd97...` -> #871
+> `645a5b09...` -> #872 `57206ce8...` -> #873 `b25b3874...` -> #874
+> `ac531c41...` -> #875 `c2278234...`, with forks #876 `259e2d1a...` and
+> #877 `677643a4...`; reconstructed successors #1033 `6db5cb71...` -> #1034
+> `5015f193...` preserve valid #878/#879 intent. PR bodies for this suffix were
+> corrected to the live base/head authority and no longer claim #859's repaired
+> consumer-test RED is still active. All remain Draft because current validation /
+> local intentional REDs are unresolved; no ancestor receipt transfers.
+>
+> #1057 remains the separate hosted PostgreSQL + Keycloak + Valkey authenticated
+> bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the runtime-version
+> source repair and #1056 retains immutable release/SBOM/provenance/
+> reproducibility/rollback acceptance. No release is admitted by this overlay.
+> Older overlays below are dated evidence only.
+
+
+> Live-authority overlay: 2026-09-13 16:54 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.
+> Customer Master ownership issue #1052 / PR #1055 is on exact
+> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation
+> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94`
+> exposed a real repository RED after shared eligibility SQL qualification:
+> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two
+> failures were the corroborated-association/reused-catalog unit tests. Their
+> fake query recognizers still expected old unqualified capture/revalidation
+> SQL, so they returned no evidence after production queries were correctly
+> qualified with `source_post.*`; the scope-change test also stopped reaching
+> its intended revalidation phase.
+>
+> Causal commit `50c4935e...` changes only those unit-fake recognizers to the
+> canonical qualified SQL. Production authorization, persistence, locking,
+> provider/model selection and workflow gates are unchanged. Fresh exact-head
+> validation materialized without no-op churn. Frontend lint/test/build/
+> Storybook, Security `34746058657`, and SAST `34746058639` are GREEN. Full
+> PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, Noema
+> `34746057619`, and Strix `34746057545` were still live at this snapshot;
+> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review
+> receipt transfers, and #1055 is not merge-ready.
+>
+> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/
+> ABAC hosted-topology owner. Central workflow repair remains `.github#1929/
+> #2106` for CodeQL producer/consumer settlement and `.github#2045/#2109` for
+> Ready-transition/model-review reconciliation; LineageWeave does not copy
+> those owner implementations. Draft #961 remains the package/runtime-version
+> source repair and #1056 carries immutable release/SBOM/provenance/
+> reproducibility/rollback acceptance. Protected main still has package/
+> frontend `2.28.0` versus runtime `2.20.0` until normal integration. No
+> release is admitted by this overlay. Older overlays below are dated evidence only.
+
+
+> Live-authority overlay: 2026-09-13 15:24 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.
+> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact
+> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run
+> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract
+> RED, applied the minimal serializer/E2E expectation repair, obtained focused
+> GREEN, and published a self-cleaning ordinary commit. The current head adds
+> `tests/test_customer_master_hint_response_contract.py`, updates the real-service
+> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow.
+> All #1055 inline review threads are resolved.
+>
+> Current-head central workflow identities are Draft lifecycle `action_required`,
+> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca`
+> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required
+> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and
+> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains
+> open for unchanged-head Draft-to-Ready materialization, so no empty commit or
+> lifecycle-flip loop is used to manufacture current-head evidence.
+>
+> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture
+> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is
+> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/
+> #1049/#1046 remain Draft under their own live authority. Protected-main release
+> identity source repair is existing Draft PR #961 at exact
+> `3bdec0504a65e63f44bd49ba15de37182a1672cc`; issue #1056 now converges release,
+> SBOM, provenance, reproducibility and rollback acceptance onto that single writer
+> rather than spawning a competing lane. Protected main itself still reports
+> `pyproject.toml` 2.28.0 versus runtime `lineageweave.__version__` 2.20.0 until
+> normal integration. OpenTelemetry and PostgreSQL warning owners remain #1036/#973
+> and #1038/#1040. No release is admitted by this overlay. Older overlays below are
+> dated evidence only.
+
+
+> Live-authority overlay: 2026-09-13 12:11 KST. Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`;
+> inventory is 159 open PR / 36 open issue.
+> Customer Master ownership repair #1055 is Ready validation admission at exact
+> `08a08108a87657ad427a6b6fa9b1b327166b0c9e`. Current repair separates source-post corporate/process
+> authorization ownership from corroborated customer identity and delegates corporate
+> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010,
+> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct
+> insert. Source authorization locks are reacquired only for the short exact-source
+> revalidation/persistence transaction after external corroboration/catalog resolution.
+> Validation evidence from predecessor heads does not transfer across this head.
+>
+> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless
+> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report
+> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer
+> Master relationship code. Canonical central workflow defects remain `.github#1929`
+> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head
+> Ready reconciliation). Protected-main release metadata is still blocked by the
+> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch;
+> no release is admitted from this overlay. Older overlays below are dated evidence.
+
+
+> Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still
+> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint
+> ownership repair #1055 now has final causal head
+> `b26e5391d087e2e9610a8c0d52eaeb68f1f912a7`. Predecessor `7dbd1333...`
+> completed repository/full-PostgreSQL Tests, Security, SAST, dynamic CodeQL,
+> Noema and Strix successfully but remained blocked by Required CodeQL/OpenCode;
+> it returned to Draft before further changes, and those receipts do not transfer.
+>
+> Three ordinary non-force follow-ups close the remaining docstring/test-contract
+> acceptance without changing Customer Master production semantics: focused unit
+> helpers now have meaningful docstrings and assert the exact association INSERT
+> tuple, the live PostgreSQL ownership proof is documented, and
+> `tests/test_customer_hint_docstring_contract.py` AST-enforces docstrings on every
+> production function owned/touched by this repair. #1055 is Ready only as exact-head
+> validation admission. The causal `b26e5391...` push materialized ten fresh lanes,
+> including repository Tests/Security/SAST/CodeQL, dynamic CodeQL/Code Quality,
+> Required scheduler, Strix, OpenCode and Noema; they are currently queued/running.
+> No predecessor GREEN or approval counts toward promotion.
+>
+> #1042, #1054, #1047, #1049 and #1046 remain Draft. #1042's real Medium CWE-862
+> period-report aggregate finding remains owned by #1050/#1054 rather than duplicated
+> into Customer Master relationship-network code. Canonical central workflow defects
+> remain `.github#1929` (CodeQL producer/consumer ordering) and `.github#2045`
+> (unchanged-head Ready reconciliation). Protected-main release metadata remains
+> inconsistent (`pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0),
+> so no release is admitted. PR #1041 remains Draft; older overlays are dated evidence.
+
+> Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit
+> repair #1042 is now Draft at exact
+> `f23f5a567bd66113603837f86f030c3c459e69e6`: Strix `34721720240`
+> terminalized FAILURE after setup and scan execution. Immutable artifact
+> `10309695301` (95,509 bytes,
+> `sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8`)
+> contains one real Medium CWE-862 finding: mixed-visibility project/thread/team
+> period-report endpoints could disclose full-population stored aggregates when
+> at least one contributor remained visible. That defect is already isolated in
+> #1050/#1054; #1054 is the security prerequisite and report authorization is not
+> duplicated into #1042. Future #1042 integration requires a non-force descendant
+> restack/reconstruction after that prerequisite lands.
+>
+> Customer-hint ownership repair #1055 is on exact
+> `7dbd133320d8b12bde394569955e0ae6503f8f39`. Predecessor repository validation
+> reached 1771 passed / 147 skipped and then exposed two owned REDs: migration
+> 0250 was not replay-safe and the static SQL-review ledger still expected 36
+> suppressions after the repair legitimately removed one. Exact head now uses
+> `CREATE TABLE IF NOT EXISTS` / `CREATE INDEX IF NOT EXISTS` and tracks 35
+> reviewed suppressions. Security `34731558854`, SAST `34731558875`, dynamic
+> GitHub CodeQL `34731558343`, and Code Quality `34731558308` are GREEN.
+> Repository Tests `34731586226`, Required Noema `34731558900`, and Strix
+> `34731558917` are still live. Required CodeQL `34731558861` failed because
+> compatibility consumers terminalized before the producer dispatch later
+> succeeded; canonical owner `.github#1929` carries the unchanged-head canary.
+> Required OpenCode `34731558957` failed closed without a current-head verdict.
+> #1055 is Ready only as a live validation admission, not a merge-ready claim.
+>
+> #1054 remains Draft at `4519c101f13e08c10653b95ff88d66b4ce47f0b8` with
+> repository Tests GREEN and central unchanged-head workflow reconciliation owned
+> by `.github#2045`. Protected-main release metadata remains inconsistent:
+> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares 2.20.0.
+> No release is admitted while that blocker or any current required gate remains.
+> PR #1041 remains Draft; every older overlay below is dated evidence only.
+
+
+> Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified
+> commit signature. Fresh non-Draft inventory contains exactly #1042 and #1055;
+> both are validation admissions only, not merge-ready claims.
+>
+> Customer Master process-unit repair #1042 remains at exact
+> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST
+> are terminal GREEN while Required CodeQL/OpenCode/Noema are terminal FAILURE.
+> Strix `34721720240` is still genuinely in progress on the unchanged head, so
+> elapsed time alone is not used to cancel it. If that lane terminalizes while
+> authoritative failures remain, #1042 returns to Draft.
+>
+> Customer-hint ownership issue #1052 / PR #1055 advanced after review to exact
+> `e11ff8698f20afc4ac628a6a86611ad1348c3fcb`. Migration 0250 and Proposed ADR
+> 0374 keep `source_post.corporate_entity_id` / `process_unit_id` as access
+> ownership and persist resolved customer identity in
+> `source_post_customer_resolution`. Request identity is whitespace-normalized
+> for matching and corroboration while the association preserves the actual raw
+> `source_post.source_customer_code`. External resolution still runs with the DB
+> resource released; a short persistence transaction then revalidates and
+> `FOR SHARE` locks the exact captured source set before writing the association.
+> Customer Master now selects resolved id/name/status/evidence coherently from one
+> deterministic newest resolution row rather than independent aggregate maxima.
+> The bearer + PostgreSQL regression also excludes foreign same-hint evidence,
+> preserves source ownership and raw spaced hints, rejects blank HTTP hints, and
+> checks coherent newest-resolution metadata. The four validated CodeRabbit
+> findings are repaired and their outdated threads resolved.
+>
+> #1055 was marked Ready on the unchanged exact head only to admit fresh
+> validation. Repository Tests `34730379137` rematerialized; frontend
+> lint/test/build/Storybook is GREEN and the PostgreSQL job is still active.
+> Draft-time Security `34730262196`, SAST `34730262117`, and Required CodeQL
+> `34730262172` are `action_required`; no fresh central Security/SAST/Required
+> CodeQL/OpenCode/Noema/Strix identity appeared at the first Ready reconciliation
+> read. Canonical owner `.github#2045` now carries this unchanged-head canary.
+> Do not use a no-op commit, Draft/Ready oscillation, or synthetic status to
+> manufacture promotion evidence.
+>
+> #1054, #1047, #1046 and #1049 remain Draft. Protected-main release metadata
+> remains inconsistent (`pyproject.toml` 2.28.0 versus
+> `lineageweave.__version__` 2.20.0), so release remains blocked. PR #1041 stays
+> Draft; every older overlay below is dated evidence only.
+
+
+> Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports
+> 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042
+> and #1055; both are Ready only to preserve or obtain exact-head validation,
+> not as merge-ready claims.
+>
+> Customer Master process-unit repair #1042 remains on exact
+> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST
+> are terminal GREEN and Required CodeQL/OpenCode/Noema are terminal FAILURE.
+> Strix `34721720240` remains genuinely in progress on the unchanged head, so
+> elapsed time alone is not used to cancel it. If that lane terminalizes while
+> required failures remain, #1042 returns to Draft.
+>
+> Customer Master customer-hint ownership issue #1052 now has repair PR #1055
+> at exact `77e7c8bd8bacb8f0ce30dd9e5ddd71c30a7632da`. Migration 0250 and Proposed
+> ADR 0374 introduce normalized `source_post_customer_resolution`; hint
+> corroboration captures only caller-visible eligible evidence, releases its DB
+> resource before external resolution/verification, then reacquires a short
+> transaction and `FOR SHARE` revalidates the exact captured sources before an
+> idempotent association write. `source_post.corporate_entity_id` and
+> `process_unit_id` remain authorization ownership and are never rebound to the
+> resolved customer. Customer Master read models consume the normalized
+> association only after source-post ABAC. A live PostgreSQL regression covers
+> two private tenants sharing one synthetic hint and requires that only the
+> authorized tenant's source receives the resolution association while both
+> source ownership tuples remain unchanged.
+>
+> On #1055, fresh repository Tests `34729447666` rematerialized after Ready;
+> frontend lint/test/build/Storybook is GREEN and the full PostgreSQL suite is
+> still running. Draft-time central Security `34729440550`, SAST `34729440465`,
+> and Required CodeQL `34729440480` remain `action_required` and did not obtain
+> fresh identities on the unchanged Ready head. Canonical Ready reconciliation
+> owner `.github#2045` has this canary; no no-op commit, lifecycle flip loop, or
+> manual success status is used. Authenticated HTTP/E2E cross-tenant evidence,
+> central security/model gates and independent current-head approval are still
+> required before integration.
+>
+> #1054, #1047, #1046 and #1049 remain Draft. #1053 still owns Post Chat
+> read-derived compute versus shared-persistence mutation authority and must not
+> duplicate #1044/#1047 replay-disclosure ownership. Protected-main release
+> metadata remains inconsistent (`pyproject.toml` 2.28.0 versus
+> `lineageweave.__version__` 2.20.0), so protected release remains blocked.
+> PR #1041 remains Draft; every older overlay below is dated evidence only.
+
+> Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live
+> search reports 158 open PRs and 36 open issues. Exactly one open PR is
+> non-Draft: #1042, whose Ready state is validation admission only.
+>
+> Customer Master process-unit authorization remains issue #1045 / PR #1042
+> at exact `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests
+> `34721721155`, Security `34721721167`, and SAST `34721721186` are terminal
+> GREEN. Required CodeQL `34721721113`, OpenCode `34721720227`, and Noema
+> `34721720347` are terminal FAILURE. Strix `34721720240` is still genuinely
+> in progress on the same exact head, so the admission is preserved without
+> elapsed-time cancellation or source churn. The later CodeQL producer dispatch
+> succeeded only after compatibility consumers had already failed; canonical
+> owner repair remains `.github#1929` and predecessor receipts do not transfer.
+>
+> Mixed-visibility period-report authorization remains issue #1050 / Draft PR
+> #1054 at exact `4519c101f13e08c10653b95ff88d66b4ce47f0b8`. Whole-population
+> admission now suppresses a precomputed report aggregate when any persisted
+> member or leftover-pair contributor is not visible; comparison evidence carries
+> `process_unit_id`, and authenticated Keycloak + PostgreSQL regression proves
+> detail/list/comparison visible before scope contraction and suppressed after a
+> contributor becomes foreign-private. Repository Tests `34723167232` is terminal
+> GREEN, including the full PostgreSQL suite, and dynamic GitHub CodeQL reports no
+> new alerts. Draft-push central Security `34723086654`, SAST `34723086683`, and
+> Required CodeQL `34723086691` stayed `action_required`; after Ready only the
+> repository Tests identity rematerialized. With no live validation lane left,
+> #1054 returned to Draft on the unchanged head. Canonical lifecycle repair is
+> `.github#2045`; do not use empty commits, Draft/Ready oscillation, manual status,
+> or leaf-side gate weakening.
+>
+> Persisted Post Chat replay authorization remains Draft PR #1047 at exact
+> `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security,
+> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL,
+> OpenCode, Noema and Strix are terminal FAILURE. Dependency advisory
+> GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 at
+> `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`; duplicate migration ordinal
+> 0233 remains issue #1048 / Draft PR #1049 at
+> `5322971193d1ff4e0ae13c054d8f99615934d4dc`.
+>
+> Customer Master customer-hint repair remains issue #1052. ADR 0042 requires
+> source-post tenant/access ownership to stay distinct from resolved customer
+> identity and provenance; do not repair that issue by rebinding
+> `source_post.corporate_entity_id`. Post Chat shared-persistence mutation remains
+> issue #1053 and must not duplicate #1044/#1047 replay-authorization ownership.
+>
+> Protected-main release metadata is still inconsistent: `pyproject.toml` declares
+> 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release
+> blocker rather than normalizing it in documentation. ADR 0251 remains the I/O-
+> psychology authority and ADR 0256 the extensible Voice-combination contract.
+> RankWeave, ThreadWeave, TEPP, and canonical lowercase
+> `ContextualWisdomLab/disksage` retain their own bounded responsibilities.
+> PR #1041 remains Draft; earlier overlays below are dated historical evidence only.
+
+> Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is
+> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
+> explained leftover share, #775). Open ready PRs still lack independent
+> APPROVE. #782 leftover-map coordinates + graphic + axis share + ticks
+> (v2.24.0–v2.27.0 / ADR 0267–0270) is on
+> `2a203bf8b75b987ba899a0006a312d81259b9124` after #799 squash-merged
+> into the unprotected leftover branch. Auto-merge squash remains armed
+> on #782/#780/#774/#772/#771/#770. Independent APPROVE is still
+> required for protected main. Drafts remain dirty against `main`. #96
+> stays closed as a weaker duplicate of #91. GitHub writes through
+> `gh`/MCP succeed. Copilot review is not independent APPROVE. Do not
+> self-approve. Do not `gh pr merge` stacked leftover PRs onto an
+> unprotected leftover base.
+>
+> Next buyer increment on this cycle: leftover-map distance on
+> graphic-display pair segments (ADR 0271 / v2.28.0). Caption each
+> closest/farthest segment with persisted leftover-map distance `d` so
+> the pair-row badge matches the graphic line. UI-only; no new columns.
+> Missing/non-finite `d` omits that segment caption. Do not invent `d`
+> from plotted coordinates. Do not invent leftover scores. Stack onto
+> leftover branch `feat/leftover-map-coordinates-v2240`; leave the PR
+> open for independent review.
+
+> Exact-head loop overlay: 2026-08-29 13:15 KST. Protected `main` is
+> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
+> explained leftover share, #775). Open ready PRs still lack independent
+> APPROVE. #782 leftover-map coordinates + graphic display + axis share
+> (v2.24.0 / v2.25.0 / v2.26.0 / ADR 0267 / ADR 0268 / ADR 0269) is on
+> `4a0afbf4804d9862bba58869db20ccdfb0a0b37e`; Strix fail-closed and no
+> independent APPROVE. Auto-merge squash remains armed on
+> #782/#780/#774/#772/#771/#770. Drafts remain dirty against `main`.
+> #96 stays closed as a weaker duplicate of #91. GitHub writes through
+> `gh`/MCP succeed (comment/create-branch/auto-merge). `git push` HTTPS
+> still fails (empty `X-OAuth-Scopes`). Copilot review is not
+> independent APPROVE. Do not self-approve.
+>
+> Next buyer increment on this cycle: leftover-map coordinate ticks
+> (ADR 0270 / v2.27.0). Tick leftover-map axes at the origin and at each
+> unique finite persisted `ξ` / `ζ` so pair-row `ξ (x, y) ζ (x, y)`
+> matches the graphic. UI-only; no new columns. Rank-0 unused axes name
+> only `0` and do not invent drawing-scale `−1` / `+1` ticks. Do not
+> invent leftover scores. Do not mix into #782; stack onto leftover
+> branch `feat/leftover-map-coordinates-v2240`.
+
+> Exact-head loop overlay: 2026-08-28 19:15 KST. Protected `main` is
+> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
+> explained leftover share, #775). Open ready PRs still lack independent
+> APPROVE. #782 leftover-map coordinates + graphic display (v2.24.0 /
+> v2.25.0 / ADR 0267 / ADR 0268) is on
+> `2f7e9c8df695f12d03964d5caa68fa3355bdd923`; Strix fail-closed and no
+> independent APPROVE. Drafts remain dirty against `main`. #96 stays
+> closed as a weaker duplicate of #91. GitHub writes through MCP succeed
+> (comment/create-branch/git push/auto-merge). Copilot review is not
+> independent APPROVE. Do not self-approve.
+>
+> Next buyer increment on this cycle: leftover-map axis share on the
+> graphic display (ADR 0269 / v2.26.0). Caption plot axes with persisted
+> ADR 0148 `leftover_map_axes` inertia `σ_k² / Σ_j σ_j²`. UI-only; no
+> new columns. Rank-0 zero-share axes still named. Missing/non-finite
+> share omits that axis badge and keeps existing leftover-map axis
+> text. Do not invent leftover scores. Do not mix into dashboard stacks
+> #640/#778/#781.
+
+> Exact-head loop overlay: 2026-08-28 16:05 KST. Protected `main` is
+> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
+> explained leftover share, #775). Open ready PRs still lack independent
+> APPROVE. #782 leftover-map coordinates (v2.24.0 / ADR 0267) is on
+> `e2d13019004a5d8c019fecf7a39ceeef4093b8dd`; Strix fail-closed and no
+> independent APPROVE. Drafts remain dirty against `main`. #96 stays
+> closed as a weaker duplicate of #91. GitHub writes through MCP succeed.
+>
+> Next buyer increment on this cycle: leftover-map graphic display
+> of already-persisted `ξ_{1:2}` / `ζ_{1:2}` (ADR 0268 / v2.25.0).
+> UI-only; no new columns. `R̂` and `d` already are inner product and
+> length. Do not invent leftover scores. Do not mix into dashboard
+> stacks #640/#778/#781.
+
+> Exact-head loop overlay: 2026-08-28 13:00 KST. Protected `main` is
+> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
+> explained leftover share, #775). Open ready PRs still lack independent
+> APPROVE. Drafts remain dirty against `main`. #96 stays closed as a
+> weaker duplicate of #91. GitHub writes through `gh` succeed.
+>
+> Next buyer increment on this cycle: leftover-map coordinates
+> `ξ_{1:2}` / `ζ_{1:2}` (ADR 0267 / migration 0245 / v2.24.0) so
+> `R̂ = ξ · ζ` and `d = ‖ξ − ζ‖` are buyer-auditable. Do not name
+> leftover-map inner product, cosine, or length as separate columns.
+
+> Exact-head loop overlay: 2026-08-28 10:00 KST. Protected `main` was
+> `edf22ee39aee2a8481f9bda8fff59801821e79c2` (#773 similar-VOC coverage).
+> Open ready PRs: #772 (ask_time_axis coverage), #771 (fixtures/vision
+> coverage), #770 (project-history empty-state). Auto-merge squash is
+> enabled on all three; none has an independent APPROVE (only bot
+> COMMENT). Drafts #702, #679, #672, #667, #640 remain dirty against
+> `main`. #96 stays closed as a weaker duplicate of #91. Writes through
+> the Grok GitHub App now succeed (comment/close/auto-merge/update-branch)
+> despite empty `X-OAuth-Scopes`; git push is the remaining probe this
+> cycle. This overlay supersedes every older queue count below.
+>
+> Next buyer increment on this cycle: leftover-map explained leftover
+> share `e = R̂² / R²` (ADR 0266 / migration 0244 / v2.23.0) so
+> `e + s + x = 1` is buyer-auditable. Do not persist leftover-map
+> coordinates in this slice.
+
+> Exact-head loop overlay: 2026-08-28 KST. Protected `main` was
+> `bbb191924e9881a5201f1ecf63c854d92992cc1c`; seven PRs and nine issues were
+> open. PR #763 was `b51d3bd8872b` and PR #762 was `e6ca33dba1b5`; both were
+> mergeable, normal squash auto-merge was enabled, exact-head Checks were still
+> running, and no qualifying independent approval existed. PRs #702
+> (`93e7b81d096d`), #679 (`135dfe7c4266`), #672 (`a3e87a89185f`), #667
+> (`0c0f4af572a9`), and #640 (`bd73e0a43ae1`) remained draft and dirty against
+> `main`. Central ruleset 18156473 and repository no-force-push ruleset
+> 21065108 remain active. This overlay supersedes every older queue count below.
+> Checks from older heads, stacked bases, or merged PRs are not transferred.
+>
+> Current-runtime boundary: the official Compose project was healthy at the
+> HTTP health route, but its PostgreSQL schema did not yet contain
+> `source_post_voice`; therefore no current Voice-history aggregate,
+> authenticated project-history API result, or rendered authenticated UI result
+> is claimed. Older aggregate observations below remain dated supporting
+> evidence, not confirmation of this exact head. The checked repository names
+> are `ContextualWisdomLab/LineageWeave`, `RankWeave`, `ThreadWeave`, `TEPP`,
+> and lowercase canonical `ContextualWisdomLab/disksage`.
+
+> Voice-of-X delivery snapshot: 2026-08-27 KST. Protected `main` was
+> `ff7431bd1851c03e737808d22c6a2d43968582f9`; PR #713 was
+> `850494c3861703862a76cfe564381a41243c6c2d`; stacked PR #717 was
+> audited at implementation head
+> `d5fe4828e9005f0157c308e8ea3c3a590cdf465b`. This candidate and the
+> historical evidence below are not protected-main release evidence.
+> Loop snapshot: 2026-08-27. Protected `main` advanced through the
+> I/O-Psychology job-family and occupational-classification delivery: PRs
+> #709 (DOT/FJA worker functions, ADR 0232), #718 (evidence-bound construct
+> classes, ADR 0248), +#726 (catalog-bound construct extraction, ADR 0253),
+> #733 (construct evidence navigation, ADR 0255), #713 (Voice-of-X ADR 0246),
+> #753 (FJA I/O-Psychology semantic layer, ADR 0251), #751 (SOC/O*NET/RIASEC
+> taxonomy, ADR 0245), #749 (authorized job-family and job-series snapshot
+> import, ADR 0263), #657 (TEPP lifecycle evidence), #704, #720, and #754 are
+> now merged. The still-open queue is carried in section 1. No row below is
+> release evidence until re-verified on a specific head.
+
+## Voice-of-X product and technical gap
+
+ADR 0246 and PR #713 add Supplier, Employee, Business, Regulator, Investor,
+Society, and Process to the original Customer, Customer's Customer,
+Competitor, Market, and Partner source-post vocabulary. The migration,
+published SKOS concepts, product requirements, changelog, and ontology
+round-trip tests agree on the twelve codes. The design is organization-type
+neutral: public bodies, nonprofits, communities, and automated processes do
+not need to be forced into a B2B2C customer chain.
+
+The phrase "all Voice-of-X combinations" does not have a standards-backed
+finite enumeration. ISO's own stakeholder-category guidance says that the
+relevant category set varies by committee and subject; ISO 26000 requires
+stakeholder identification and engagement across organizational contexts;
+AA1000SES requires an inclusive, continuing identification process; and
+Mitchell, Agle, and Wood (1997) model stakeholder salience from combinations
+of power, legitimacy, and urgency rather than a fixed industry-role list.
+Accordingly, ADR 0246 keeps the controlled vocabulary extensible and refuses
+keyword inference, defaults, invented weights, or an asserted exhaustive
+cross-product.
+
+ADR 0256 and migration 0237 now define the persistence contract for
+evidence-bearing composition. A post keeps one source-provided
+`voc_type_code`, mirrored as its sole primary association, while every
+additional voice requires a normalized PROV-O assertion and explicit truth
+status. Half-open assignment intervals preserve a backfilled primary at
+historical cutoffs, close a replaced primary without deleting it, and permit a
+later return to the same Voice. The #717 candidate therefore addresses #748's
+A → B → A storage root cause without adding Cartesian-product codes. Protected
+delivery and synthetic PostgreSQL concurrency/cutoff evidence remain required.
+The remaining acceptance boundary is:
+
+1. preserve the imported primary voice without reclassification (implemented
+ in the candidate migration; migration 0237 replayed twice successfully on
+ an isolated PostgreSQL stack on 2026-08-27, including both primary-sync
+ triggers; a synthetic real-OIDC PostgreSQL API write also proved that the
+ imported primary remains unchanged);
+2. record each additional voice with its own source/evidence and truth state
+ (schema-enforced and candidate `post_admin` API plus live Post-popup
+ authoring implemented; synthetic authenticated PostgreSQL integration
+ proved denial before permission, the authorized write, and its normalized
+ PROV-O derivation on 2026-08-27);
+3. keeps post voice distinct from named-counterparty relationship, actor role,
+ topic, channel, lifecycle, and stakeholder-salience attributes;
+4. return only authorized associations through API, JSON-LD, CSV, filters,
+ and UI (candidate API list/detail, filters, combined post-card labels,
+ qualified JSON-LD, exact-value CSV, SHACL, and source-post evidence
+ navigation implemented; the board re-filter matches every associated voice
+ and all twelve governed atomic labels are localized across English, Korean,
+ Chinese, Japanese, and Vietnamese; one bounded query projects assignments
+ for every authorized Post even when another node type is the focus; post
+ detail lists primary and evidence-connected perspectives separately and
+ honors its knowledge cutoff; client-side JSON-LD filtering retains only
+ exact canonical repository-case node and Voice-assignment IRIs rather than
+ accepting cross-origin suffix matches; the exact-value row exposes distinct
+ carrying-Post and authorized derivation-evidence actions, while hidden
+ evidence emits neither an identifier nor a fabricated evidence count;
+ paged JSON-LD merges properties for one subject and unions its multi-Voice
+ relation rather than overwriting an earlier page); and
+5. proves zero-, one-, and multi-voice states with synthetic fixtures,
+ migration replay, ontology/SHACL, API, accessibility, and Storybook edge
+ tests before any release claim. The candidate `CombinedVoiceEvidence` scene
+ covers primary-plus-additional assignments; desktop and mobile screenshots
+ were inspected on 2026-08-27. At 390 CSS pixels the document did not
+ overflow, the named exact-value region remained horizontally scrollable,
+ and the source-post evidence action remained visible and labeled. The
+ `Post/Recorded perspectives` desktop and 390-pixel scenes were also inspected
+ on 2026-08-27; both kept each complete Voice label paired with its imported
+ or evidence-connected state without clipping or horizontal overflow. The
+ `Post/Connect perspective` ready/success scenes were inspected at 1440 and
+ 390 CSS pixels on 2026-08-27: labels stay above controls, the mobile form is
+ a single column, controls meet the 44-pixel touch target, and no horizontal
+ overflow was visible.
+
+At this snapshot the repository had 42 open PRs and 11 open issues. PR #713
+head `850494c3` includes the review-driven localization of all twelve governed
+Voice labels. Its frontend, ontology publication, static-analysis, dependency,
+coverage, full-suite, CodeRabbit, Devin, and OpenCode checks passed. Strix
+failed closed before producing a vulnerability report:
+the primary NVIDIA NIM model returned HTTP 429, one configured fallback had
+reached end of life, and the OpenAI fallback reported exhausted credits. A
+same-head retry completed on 2026-08-27 with the explicit
+`STRIX_PROVIDER_UNAVAILABLE` annotation and again produced no vulnerability
+report. This
+is provider/control-plane unavailability, not a vulnerability result or
+permission to transfer an older success. Auto-merge remains enabled, while an
+independent approval is still required. PR #717 implementation head
+`d5fe4828` merges that
+parent change without force-pushing and separates the complete governed Voice
+catalog used for authoring from usage-derived Board filters, so an authorized
+administrator can attach a Voice that no visible Post carries yet. It also
+labels Voice exact-value navigation as opening the carrying Post rather than
+misrepresenting that Post as the separately recorded derivation evidence. Its
+CodeRabbit and hosted Frontend/Storybook checks passed at predecessor head
+`ebb4ef1d`; refreshed checks for exact head `d5fe4828` were queued. Focused local
+backend tests, frontend type checking/lint, and the new unused-Voice authoring
+regression passed, and the exact-value navigation tests, lint, and type check
+passed after the label repair. The paged JSON-LD union regression and Voice
+evidence navigation suite passed 23 focused frontend tests; 48 focused backend
+ontology/docstring tests also passed. The full backend suite at predecessor
+head `ebb4ef1d` passed 1,366 tests with 148 environment-dependent skips. The
+real-integration fixture now applies
+the existing migration 0042 before the expanded taxonomy migrations instead
+of seeding an incomplete or duplicate legacy catalog; the exact
+`d5fe4828` authenticated post-list integration passed in 91.54 seconds. The
+wider local frontend run had 400 passes and eight five-second timeouts under
+concurrent backend-suite load; a later App-only run had 94 passes and five
+five-second timeouts, while the hosted Frontend/Storybook job passed on
+`ebb4ef1d`. Neither local timeout run is promoted to full-suite success. An initial
+authenticated integration attempt was unavailable while Keycloak initialized;
+a later retry against the shared synthetic stack succeeded in 56.18 seconds
+and proved the permission, API, PostgreSQL,
+PROV-O, and primary-preservation assertions; no identifying source data was
+used or retained. No self-approval, admin bypass, or stale-head check transfer
+is permitted.
+
+Stacked PR #717 carries ADR 0256, migration 0237, qualified
+ontology terms, persistence/API/UI tests, and the category-validation review
+repairs plus a local candidate admin write path that creates its PROV-O
+derivation from an authorized evidence Post. Its JSON-LD projection names that
+evidence Post only when it is in the authorized visible set and omits the whole
+additional assignment otherwise, preserving the SHACL evidence minimum without
+substituting the assigned Post. It targets
+#713's branch, not protected `main`;
+its checks and review are candidate evidence only. After
+#713 reaches protected main, #717 must be synchronized, retargeted to `main`,
+and revalidated on its then-current head.
+
+Downstream Dashboard repair PR #737 exact head `a837ee5d` is stacked on base
+`7c7bb2cf`, which contains migration 0235 through a non-#713 composition but
+does not contain #713's twelve-label locale update. Its added Voice labels are
+therefore necessary on that exact base, yet overlap #713 and must be reconciled
+when the stack is eventually rebuilt on protected `main`; neither branch is a
+second taxonomy authority, and pre-parent Checks cannot transfer across that
+restack.
+The remaining user-visible gap is evidence-bearing composition. A post still
+has one source-provided `voc_type_code`; the product cannot yet represent a
+single record that intentionally carries multiple independently evidenced
+voices, nor expose the combination in filters, exports, or the ontology
+neighborhood. Do not solve this by adding every Cartesian-product code. The
+acceptance boundary for a later ADR is a normalized, provenance-bearing
+multi-voice association that:
+
+1. preserves the imported primary voice without reclassification;
+2. records each additional voice with its own source/evidence and truth state;
+3. keeps post voice distinct from named-counterparty relationship, actor role,
+ topic, channel, lifecycle, and stakeholder-salience attributes;
+4. returns only authorized associations through API, JSON-LD, CSV, filters,
+ and UI; and
+5. proves zero-, one-, and multi-voice states with synthetic fixtures,
+ migration replay, ontology/SHACL, API, accessibility, and Storybook edge
+ tests before any release claim.
+
+At this snapshot the repository had 23 open PRs and 10 open issues. PR #713
+was `MERGEABLE` but policy-blocked: exact-head backend, frontend, CodeQL,
+ontology-publication, Semgrep, OSV, Trivy, Scorecard, Noema, Devin, and
+CodeRabbit checks were successful; `coverage-source-tree` was queued; Strix
+failed closed with `STRIX_PROVIDER_UNAVAILABLE`; and an independent approval
+was still required. Auto-merge remains enabled. No self-approval, admin bypass,
+or stale-head check transfer is permitted.
+
+References for this gap use the APA 7 entries in ADR 0246. Current supporting
+standards pages were rechecked on 2026-08-27: ISO 26000:2010 remains applicable
+to all organization types and AA1000SES v3 is under development for a planned
+2027 release, so the repository continues to cite the published AA1000SES
+(2015) contract rather than treating the draft as adopted policy.
+
+> Current queue overlay: 2026-08-27 KST. Protected `main` was
+> `ff7431bd1851c03e737808d22c6a2d43968582f9`; 26 PRs and 10 issues were
+> open. This overlay supersedes the older queue count and exact-head table
+> below, which remain historical evidence. Re-fetch the head, checks, reviews,
+> threads, applicable rulesets, and merge SHA immediately before any lifecycle
+> claim. No local branch or stacked-branch result is protected-main evidence.
+
+## Current occupational semantic-layer gap
+
+ADR 0245's candidate branch publishes only a provenance-safe classification
+foundation: 23 2018 SOC major groups, four O*NET 31.0 Job Zone categories, six RIASEC interest
+types and their published adjacency, six explicitly legacy work-value clusters, seven
+revised work-style dimensions, and four ability domains. It asserts no
+occupation-to-characteristic instance profile and therefore does **not** yet
+satisfy the requested job-family, job-series, and occupation-level coverage of
+work cognition, affect, behavior, or their empirical relations. This is an
+explicit unavailable state, not a reason to infer mappings from labels.
+
+| Gap | Current evidence | Acceptance requirement |
+|---|---|---|
+| Classification depth | ADR 0245 and `lineageweave/io_taxonomy.py` expose SOC major groups only; schemes now name versioned PROV source entities and the stable O*NET 31.0 Job Zone JSON digest | Import a versioned authoritative classification release with provenance-preserving major, minor, broad, and detailed occupation identifiers; add ISCO/ESCO crosswalks only where the publishing authority supplies them |
+| Construct granularity | The candidate ontology exposes 23 high-level characteristic concepts | Publish source-versioned O*NET abilities, skills, knowledge, work activities, work context, interests, and work styles without collapsing cognition, affect, and behavior into one dimension; preserve removed Work Values only as versioned legacy content |
+| Occupation-to-construct relations | ADR 0245 deliberately declares relation properties without instance assertions | Persist released source observations with source version, occupation code, element identifier, scale identifier, value, sample/error metadata when supplied, and provenance; never invent or locally normalize a weight |
+| Job-family and job-series semantics | No authoritative employer-specific job architecture is present | Define an organization-neutral import contract that preserves the authorized source hierarchy and distinguishes standard occupation codes from employer job families/series; no label-based binding |
+| Temporal and multilevel interpretation | Static vocabulary only; no person-level inference is asserted | Version valid and transaction time, preserve occupation/organization/unit nesting and multiple membership, and require TEPP or the owning Rust psychometric service before any calibrated temporal or multilevel result |
+| Product consumption | The read model has no persisted semantic-layer consumer or authenticated UI evidence | Add a provenance-bearing API and accessible ontology exploration flow, then verify synthetic Storybook edge states plus authenticated aggregate runtime evidence without exposing identifying records |
+
+### Current exact-head PR queue
+
+| PR | Exact observed head | Base | Observed gate state |
+|---:|---|---|---|
+| #719 | `0cea830a` | `feat/fja-worker-function-ontology` | unstable; 1 pending check(s) |
+| #718 | `a3fb32bb` | `feat/fja-worker-function-ontology` | clean; no non-passing check observed |
+| #717 | `771a8edf` | `feat/voice-of-x-complete-taxonomy` | unstable; 1 pending check(s) |
+| #716 | `8b54b2f7` | `fix/structured-workflow-exact-pin` | clean; no non-passing check observed |
+| #714 | `aa93318f` | `main` | blocked; no non-passing check observed |
+| #713 | `cc3dfc14` | `main` | blocked; review required; 13 pending check(s) |
+| #711 | `8902e37f` | `feat/dashboard-case-metrics` | clean; no non-passing check observed |
+| #710 | `8df04b68` | `main` | blocked; review required; no non-passing check observed |
+| #709 | `8ef4090c` | `main` | blocked; review required; 11 pending check(s) |
+| #704 | `027323cf` | `main` | blocked; review required; 2 failed check(s) |
+| #702 | `5de66ab9` | `main` | blocked; review required; 2 pending check(s) |
+| #701 | `cc3351a9` | `main` | blocked; review required; 1 failed check(s) |
+| #700 | `1bc99eca` | `main` | blocked; review required; 1 failed check(s) |
+| #680 | `efe864e5` | `main` | blocked; 1 failed check(s) |
+| #679 | `13ecf41d` | `main` | blocked; no non-passing check observed |
+| #672 | `a3e87a89` | `main` | blocked; review required; 1 failed check(s) |
+| #668 | `1194f44d` | `main` | blocked; review required; 1 failed check(s) |
+| #667 | `c2d11a8a` | `main` | blocked; review required; 2 pending check(s) |
+| #658 | `15d670f0` | `main` | blocked; review required; 1 failed check(s) |
+| #657 | `9f71681c` | `main` | blocked; review required; 1 failed check(s) |
+| #644 | `f53dd28e` | `main` | blocked; review required; 1 failed check(s) |
+| #643 | `8767de1b` | `main` | blocked; review required; 1 failed check(s); 1 pending check(s) |
+| #640 | `5594029c` | `main` | blocked; no non-passing check observed |
+| #639 | `2f4b1bff` | `main` | blocked; review required; 1 failed check(s) |
+| #632 | `24262a99` | `main` | blocked; review required; 1 failed check(s) |
+| #629 | `b721b0f2` | `main` | blocked; review required; 1 failed check(s) |
+
+> Dashboard delivery snapshot: 2026-08-26 07:15 KST. Protected `main` was
+> `494b54e2245040bcf02b45376f221c37cd437e76`. This local branch is not
+> protected-main release evidence.
+
+## Operations Dashboard PRD/TRD traceability
+
+| Requirement | Evidence contract | Delivery state |
+|---|---|---|
+| Claim cause delay: order, specification change, originating order, sales pool, Event/post counts | ADR 0206; contextual-orchestrator case classification with cited spans; Event Lineage context | Candidate implementation; authenticated runtime acceptance pending |
+| Rebid/handover: discussion, counterparties, our owner, decisions, Event/post counts | ADR 0206; normalized case facts plus persisted summary actions/roles | Candidate implementation; corpus backfill pending |
+| External information count/rate and sales/project relation | ADR 0206; semantic `external_information` classification inside Dashboard GNB | Candidate implementation; no separate Board by product decision |
+| Project-specific journey | Explicit source/semantic project membership plus event-time ordering | Candidate API and ordered journey UI implemented; authenticated runtime acceptance pending |
+| Repeat issue to design improvement | `repeat_issue`, `issue_pattern`, and `improvement_action` cited facts | Candidate semantic contract; design-system connector acceptance pending |
+| Natural-language Ask with evidence, report, alert, MCP | Persisted semantic-unit embeddings plus versioned delivery/resource contract | Candidate implementation uses whole-question embedding retrieval with no lexical fallback; authenticated runtime acceptance pending |
+| Similar VOC, customer cohort, prior action | Persisted repeat-issue candidate semantics plus orchestrator pair adjudication and extractive evidence | Candidate live post endpoint and post-detail UI implemented; authenticated runtime acceptance pending |
+| TEPP independent Event Lineage anchor | Accepted, persisted TEPP criterion bound to exact snapshot/cutoff before fast-mlsirm activation | Consumer PR #606 is on protected main; TEPP producer PR #237 remains open, so no end-to-end accepted artifact is release evidence yet |
+| Temporal Lineage topics and multilevel important posts | ADR 0210; TEPP posterior topic/plausible-value contract followed by fast-mlsirm observed-information case-deletion influence | Product/technical contract is protected on `main`; neither required Rust CPU/GPU producer envelope is shipped, so the Dashboard surface remains unavailable (ADR 0208: no local Python substitute) |
+
+### Technical contract and flow
+
+```mermaid
+sequenceDiagram
+ participant Source as Authorized source_post
+ participant CO as contextual-orchestrator
+ participant Case as operations_case_* (3NF)
+ participant TEPP as TEPP criterion run
+ participant MLS as fast-mlsirm
+ participant API as Dashboard/Ask API
+ Source->>CO: semantic units + lineage + ontology context
+ CO-->>Case: cases, cited facts, session provenance
+ Source->>TEPP: versioned snapshot and independent criterion
+ TEPP-->>MLS: exact accepted anchor only
+ MLS-->>API: anchored vector or unavailable
+ Case-->>API: ABAC-filtered evidence and counts
+```
+
+Security/operability: every aggregation applies `post_read` plus row-level
+corporate-entity visibility before counting; source-body digests invalidate
+stale inference; provider errors persist no positive/negative result; PII
+remains authorized at the UI boundary and is excluded from telemetry. The
+tables use composite keys and bounded kind-first indexes; production hot-path
+acceptance still requires `EXPLAIN (ANALYZE, BUFFERS)` on an anonymized runtime
+snapshot.
+
+### Historical UI audit evidence
+
+The `f0b96029` Storybook build was rendered at 1440×1100 and 402×1200 with
+synthetic evidence; `416fd19d` changes only post-navigation request isolation.
+Desktop inspection showed all four case kinds, five non-conflated metrics,
+project-journey ordering, cited facts, and evidence actions without horizontal
+card overflow. Narrow inspection showed two-column metrics, readable cards and
+44px-class actions; the project journey remains intentionally horizontally
+scrollable. No identifying runtime record or screenshot is committed. The
+`EvidenceReady`, `NarrowViewport`, `AnalysisPendingAndMissingEvidence`,
+`AnalysisFailed`, and `LoadError` scenes cover the ADR 0206 state inventory.
+Authenticated authorized-corpus acceptance remains separate and may return
+only aggregate, non-identifying evidence to this repository.
+
+### Exact open-PR boundary
+
+At this snapshot there were 11 open PRs and 10 open issues. PRs #660 and #659
+merged to protected `main`; PR #666 remains only non-default-branch stack
+composition inside #663. Every remaining open head required refreshed hosted
+gates and/or independent review after the base changed. These observations are
+not merge readiness. Re-fetch exact heads, unresolved threads, checks,
+approvals, rulesets, and merge SHA before any lifecycle claim.
+
+> Audit snapshot: 2026-08-26 07:15 KST (refreshed by the autonomous merge
+> loop). This repository records synthetic fixtures and aggregate,
+> non-identifying runtime evidence only. Open PRs and local checks are not
+> protected-default-branch release evidence. Identifying post identifiers,
+> organization names, and production record keys must never appear in this
+> file.
+
+## 1. Exact-head and governance evidence
+
+The protected default branch was `494b54e2245040bcf02b45376f221c37cd437e76`
+when this baseline was refreshed. The live queue contained 11 open PRs and 10
+open issues. The exact-head inventory below supersedes older per-PR snapshots
+elsewhere in this document; those older rows remain useful historical delivery
+context only.
+
+| PR | Exact observed head | Merge/check state at this snapshot |
+| ---: | --- | --- |
+| #667 | `3bc662d7` | refreshes protected-main and open-queue documentation evidence; base conflict remains to be repaired |
+| #663 | `6fd2f701` | combined Project ontology candidate plus #666's non-default-branch removal of sampled region-coverage arithmetic; base conflict remains to be repaired |
+| #658 | `f007a5ed` | evidence-honest Global Ask cutoff; hosted checks and independent review required |
+| #657 | `2d9b43b7` | TEPP asynchronous lifecycle persistence while unpublished producer work stays unavailable; hosted checks and independent review required |
+| #644 | `ed8d97f3` | native frontend surface code splitting; hosted checks and independent review required |
+| #643 | `7fb4d18c` | shared token-backed status notice; hosted checks and independent review required |
+| #640 | `2d50fa01` | dashboard case metrics and project journeys; base conflict remains to be repaired |
+| #639 | `48065ad1` | restores Running action and Compose contracts; hosted checks and independent review required |
+| #632 | `29aee18d` | graph-fact provenance, public verification, MCP admission, and k6 evidence; hosted checks and independent review required |
+| #631 | `665046dc` (observed parent) | decomposes closed PR #490; this merge refresh advances its head and restarts hosted review evidence |
+| #629 | `0138db5f` | provider-work release and bounded landing reads refreshed onto protected `main`; hosted checks and independent review restarted |
+
+No row above is merge evidence. Immediately before any lifecycle action,
+re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head
+check conclusions. In particular, queued checks are infrastructure state and
+do not transfer evidence from an earlier SHA.
+
+PR #607 first merged as `61fd631c7bb3c57113fd19763c2c43161eeb2824`
+into #606's non-default branch. PR #606 subsequently passed the protected gate,
+so the combined TEPP-consumer and operations-dashboard implementation is now
+on `main`; the still-open TEPP producer PR #237 keeps end-to-end anchor
+acceptance unavailable.
+
+PR #604 was closed unmerged after its exact OIDC repair was composed into #605;
+its green or pending checks are not delivery evidence. PR #482 merged as
+protected-main commit `464ff25002044b9d933c8eefd36c8def7ca0ffd8`
+with package conflict markers, identifying baseline records, and an OIDC
+return-context regression. PR #603 repaired the package/privacy and
+analysis-run transaction defects through protected main at `4f53190b`; the
+OIDC defect remains delivered until #604 or the composed #605 passes the
+protected gate. Protected main is therefore not yet a release candidate.
+
+PR #592 first merged as `3b3af3b4fe9c439354433a43444e05f37ab24ea3`
+into #590's non-default stack base at `2f033ba3`. The complete stack then
+passed the protected gate and #590 merged to `main` as
+`1d1379fc59d9dac6e9c8bfa4812313e3b9e8f3c8`.
+
+PR #521 merged through protected `main` as
+`3797f063b1a7396972a749aa81f23745acccbee1`; it is release evidence and no
+longer part of the open queue. That merge also left a standalone conflict
+marker and duplicated stale tail in `CLAUDE.md`; #594 repaired it through
+protected `main` as `241be2dddf657f854cb8be54fe11d4ef48d37976`.
+
+Protected main now contains the ADR 0109 OIDC return restoration from #605,
+including fragment preservation and storage fallback. The #606 dashboard
+landing must additionally route `?post=` deep links to the Board; that focused
+regression is part of the current candidate and is not delivery evidence yet.
+
+Three systemic gates currently dominate the queue:
+
+1. **Strix visibility lookup failure (org control plane).** PR #600 exact head
+ `7580bdc9` failed before scanning because the required-workflow token could
+ not resolve this public repository after six API retries. The root repair is
+ ContextualWisdomLab/.github#1320 at `3b9b2380`: ordinary PR, push, and
+ schedule runs use trusted event visibility; cross-repository dispatch keeps
+ authoritative public/private/internal visibility; private and internal
+ repositories remain on private-capable providers. The exact head also
+ composes the executable fallback contract and classifies bounded NVIDIA
+ `ServiceUnavailableError` overload evidence as retryable across configured
+ distinct models without weakening exhaustion or vulnerability fail-close.
+ A hosted fallback then completed with zero vulnerabilities but was rejected
+ because the generic warning gate treated Strix's fallback-model banner and
+ a Hugging Face unauthenticated-download notice as provider failures. The
+ current head removes only those two exact scanner notices before the
+ existing general warning and explicit 429/provider failure checks. The
+ current head also clears a foreign NVIDIA/OpenRouter endpoint before a
+ direct-OpenAI fallback while retaining an explicitly configured
+ direct-OpenAI primary endpoint. The prior full quick-gate harness, overload
+ path, 12 visibility-contract tests, and the focused cross-provider endpoint
+ contract passed; exact-head hosted revalidation remains pending. It is blocked on
+ hosted exact-head gates and independent review, so no repaired
+ protected-main Strix runtime evidence exists yet.
+2. **Strix provider unavailability (org control plane).** The central required
+ Strix scan on .github#1320 failed when NVIDIA returned `Service temporarily
+ overloaded`; the gate correctly failed closed but did not try its configured
+ distinct fallbacks because the service-unavailable classifier excluded the
+ NVIDIA provider. Exact head `3b9b2380` composes that execution repair and the
+ two exact non-fatal scanner-notice exclusions while keeping
+ incomplete exhaustion non-passing. This is still an unmerged control-plane
+ proposal, not protected-main or downstream runtime evidence.
+3. **Current-head independent approval.** The org merge scheduler requires
+ `reviewDecision == APPROVED` plus complete Strix evidence on the exact
+ head. Bot review evidence regenerates per push, so any repair push resets
+ the review clock by design; this is expected and not a bypass target.
+
+Recent protected-default-branch delivery evidence (squash merges onto
+`main`, newest first):
+
+| PR | Merged (UTC) | Delivered |
+| ---: | --- | --- |
+| #628 | 2026-08-25 12:39 | one-round-trip authorized post filter options without narrowing the complete ABAC-visible set |
+| #627 | 2026-08-25 12:35 | preserved valid k6 lifecycle evidence across setup, scenario execution, and teardown |
+| #468 | 2026-08-25 08:44 | fast-mlsirm, Keyverse, contextual-orchestrator, and TEPP integration boundaries |
+| #493 | 2026-08-25 08:44 | evidence-grounded Event Lineage isolation reasons |
+| #600 | 2026-08-25 08:44 | then-current exact-head product/technical baseline |
+| #605 | 2026-08-25 08:44 | dialog focus order, evidence readability, and OIDC return-context restoration |
+| #608 | 2026-08-25 08:43 | Naruon projection consumed by Workspace Calendar |
+| #603 | 2026-08-25 07:24 | short analysis-run transactions, session advisory locking, package-marker/privacy repair, and provider-work lease release |
+| #602 | 2026-08-25 07:24 | post-detail modal semantics, Escape close, initial focus, and opener restoration; navigation-refocus edge case continues on #605 |
+| #582 | 2026-08-25 07:24 | bounded batched cited-lineage graph fetch |
+| #588 | 2026-08-25 07:23 | named two-axis leftover-map reconstruction and raw-residual identity |
+| #482 | 2026-08-25 07:03 | corroborated SKOS companion organization chips; regressions subsequently tracked above |
+| #601 | 2026-08-25 06:38 | APA 7th PROV-O and PROV-DM references for ADRs 0011 and 0065 |
+| #595 | 2026-08-25 04:39 | audited no-draft import door, nullable updated-at fallback, and event-time import |
+| #484 | 2026-08-25 04:39 | Allen interval relations with deferred FK validation |
+| #383 | 2026-08-25 04:39 | reader-safe OTel diagnostics and service-peer-bounded session metadata |
+| #599 | 2026-08-25 04:28 | raw-residual leftover-map cross-share identity aligned without arbitrary weighting |
+| #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version |
+| #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state |
+| #591 | 2026-08-25 03:32 | prior exact-head product-gap baseline snapshot |
+| #584 | 2026-08-25 03:32 | TEPP topic-lineage consumption boundary grounded in cited temporal models |
+| #581 | 2026-08-25 03:32 | relative-time Ask filtering bound to event time |
+| #596 | 2026-08-25 03:27 | hierarchy/name-resolution deep-work timeouts aligned at 600 seconds |
+| #585 | 2026-08-25 03:27 | raw Global Ask transport exceptions replaced by bounded client-safe detail |
+| #355 | 2026-08-25 02:38 | Naruon calendar projection contract and conformance fixture |
+| #562 | 2026-08-24 02:05 | parameter-free classic RRF; deleted the last hand-picked fused score |
+| #561 | 2026-08-24 01:47 | knowledge-graph precedence/hierarchy relation classification and layout order |
+| #555 | 2026-08-24 01:29 | per-channel score breakdown persisted on `post_lineage_edge.channel_scores` (ADR 0195) |
+| #559 | 2026-08-24 01:26 | deleted `DEFAULT_CHANNEL_WEIGHTS` hand-picked fallback |
+| #549 | 2026-08-24 00:43 | clamped embedding cosine into `[0, 1]` instead of remapping from `[-1, 1]` (ADR 0190) |
+| #548 | 2026-08-24 00:37 | mid-reconstruction provider failure maps to an explicit unavailable state |
+| #544 | 2026-08-24 00:27 | fusion weights accepted only via fast-mlsirm estimation |
+| #538 | 2026-08-23 23:39 | real embeddings wired into the Event Lineage text channel |
+
+This documentation is owned by protected `main` again: the #426 stack landed,
+so hidden-stack merges (#494, #497, #499, #505, #509 into unprotected parent
+branches) are historical context only and no longer gate anything.
+
+The current protected-`main` and exact #507 trees are clean of the private
+runtime source-table identifier present in the closed #506 head and older
+public history. Do not reproduce or hint at its value. Historical remediation
+requires the ADR 0001 incident process and security/privacy-owner coordination;
+never force-push or delete evidence ad hoc.
+
+The Grok durable hourly loop and the central thin GitHub Actions caller
+ContextualWisdomLab/.github#1259 (minute 4, `pr-review-fix-scheduler.yml`)
+both target this repository. Do not add a LineageWeave-local duplicate
+workflow. ContextualWisdomLab/.github#1258 merged at exact head `897819c4` to
+repair the pnpm/coverage-evidence workflow; newly created exact PR heads must
+still prove the runtime behavior because merged workflow source alone is not
+check evidence.
+
+Figma design-system boundary (ADR 0002): File ID `1Su3lDRmiZdcUs47t1QwIX`.
+The sanitized file now contains synthetic Event Lineage desktop (`5:14`) and
+mobile (`5:15`) frames with graph direction, event dates, an inference
+boundary, and exact fused-score evidence. Do not copy source-organization
+content into this repository. Storybook remains the executable scene and
+edge-case inventory for repeated web objects; rendered code-to-Figma parity
+still requires same-viewport browser comparison on an exact candidate head.
+
+## 2. User-visible capability baseline
+
+Substantially present on protected `main`:
+
+- PostgreSQL-backed import, normalized provenance, cutoff-aware analysis runs,
+ source revisions, lineage reconstruction, and explicit unavailable states.
+- Authenticated workspace navigation, post detail, localized summaries, 5W1H,
+ R&R/Keyman, evidence citations, chat, organization hierarchy, and lineage DAG
+ (`frontend/src/LineageDag.tsx` is on `main`; the old “DAG view missing”
+ baseline entry is stale).
+- Semantic paragraph/list/table/image-region units that preserve the source
+ representation and provenance instead of flattening it into one body string.
+- FJA→I/O-Psychology semantic layer (ADR 0251): the published DOT/FJA
+ Data/People/Things worker functions (ADR 0232) project into disjoint
+ cognitive, affective, and behavioral constructs with APA 7th anchors,
+ SHACL validation, and a deterministic typed read model
+ (`lineageweave/iopsy_taxonomy.py`); no fitted weight or O*NET/ADR 0248
+ crosswalk is asserted (ADR 0145).
+- Contextual-orchestrator boundaries for adjudication, extraction, summaries,
+ chat, embeddings, and VISION; null channels remain unavailable and are
+ dropped from score fusion.
+- W3C PROV-O projection through normalized provenance tables, with the
+ knowledge graph retained as an explicit navigation projection.
+- Keyverse/Keycloak OIDC, RankWeave fusion port, TEPP measurement client,
+ ThreadWeave tree assembly.
+
+These statements describe source capability, not authenticated production
+corpus acceptance or protected release.
+
+## 3. Historical open-PR inventory (superseded by §1)
+
+Heads below are queue evidence captured at snapshot time; recheck SHA,
+checks, unresolved threads, and independent approval immediately before any
+merge claim. Do not self-approve, force-push, or transfer stale review
+evidence across heads. The org merge scheduler merges only when
+`reviewDecision == APPROVED` on the exact head and Strix evidence is complete.
+
+### 3.0 Shared systemic gate
+
+| Gate | Evidence | Durable repair |
+| --- | --- | --- |
+| Strix provider unavailability | `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` and `openai-direct/gpt-5.6-luna` failed authoritatively across unrelated heads | ContextualWisdomLab/.github#1263 at `ab3d7645` proposes executable Azure/cross-provider fallbacks but remains open/conflicting; repair that branch without weakening the required gate |
+| ADR 0109 login repair debt | Eight branches cut from the pre-repair base carried the unauthenticated `AdminPanel` + unused-OIDC-helper `tsc -b` failure | Same verified two-line repair applied to #521, #522, #552, #553, #554, #556, #558, #560 during this loop; frontend lint/test/build verified locally |
+
+### 3.1 Workspace root and product surfaces
+
+| PR | Head | Intent | Notes |
+| ---: | --- | --- | --- |
+| #258 | `f0b5234d` | Workspace evidence board and source-grounded ontology surface (root stack) | Largest surface; historical CHANGES_REQUESTED is stale relative to current head |
+| #349 | `bef4a858` | Bounded ontology and provenance explorer (v2.13.0) | Issue #341 |
+| #355 | `2f3f308c` | Naruon event projection contract | Issues #336/#338 |
+| #387 | `5ef0f2e6` | Persist and explain Event Lineage channel evidence | Issue #274 |
+| #405 | `ec62d9f0` | Persisted image-region locations (v2.12.8) | VISION region provenance |
+| #484 | `878c4a87` | Allen interval relations on Event Lineage edges (v2.15.0) | Temporal modeling; Allen (1983) |
+| #490 | `d0cad030` | Wire remaining ADR 0133–0137 surfaces | Consolidated product stack incl. Knowledge Graph token repair |
+| #493 | `499c8b1b` | Name Event Lineage isolation reasons (v2.16.0) | Honest unavailable/failed states |
+
+### 3.2 SKOS organization aliases and leftover-map family (stacked)
+
+| PR | Head | Intent |
+| ---: | --- | --- |
+| #480 | `f18b421d` | Bind corroborated SKOS org aliases to one catalog row |
+| #482 | `c38c08d6` | Corroborated SKOS companion caption on organization chips (v2.14.0) |
+| #481 | `32944979` | Persist leftover interaction-map coordinates (v2.12.7) |
+| #485 | `dcaa6320` | Leftover pair clicks land on the named Post quality criterion (v2.12.8) |
+| #518 | `3117823f` | Name leftover complete-case coverage (v2.12.17) |
+| #519 | `31c150c8` | Persist leftover-map axis share on period reports (v2.12.16) |
+| #521 | `40677c75` | Leftover pairs on the grouping comparison strip (v2.12.17) |
+| #522 | `9be3712e` | Leftover-map distances on two Gabriel axes (v2.12.18) |
+| #535 | `1fb5d69a` | Name leftover-map unexplained leftover (v2.12.26) |
+| #537 | `9a639554` | Name leftover-map unexplained share (v2.12.27) |
+| #539 | `740629d0` | Name leftover-map explained share (v2.12.28) |
+| #563 | `740d50f3` | Name leftover-map cross share (v2.12.29) |
+| #564 | `ac5de72a` | Name leftover-map reconstruction share (v2.12.30) |
+
+The leftover-map naming series (#518–#564) is a stacked ladder of honest
+leftover-pair labeling increments; merge in ascending order once each exact
+head clears gates.
+
+### 3.3 Repairs and operability
+
+| PR | Head | Intent |
+| ---: | --- | --- |
+| #393 | `4ddd3a83` | Detach provider parse error context (honest orchestrator failure) |
+| #394 | `cf9505b7` | Preserve source indentation evidence for adjudication |
+| #434 | `01d6cca5` | Wire adjudication client into corpus-wide rebuild (issue #289) |
+| #541 | `3d93ea9b` | Bootstrap repo-root sys.path in operator scripts |
+| #546 | `d210c20c` | Strip Keycloak OIDC callback params from post share links |
+| #547 | `fb7fe2db` | Shorten orchestrator healthcheck retry budget |
+| #552 | `89000280` | Footer text contrast passes WCAG 1.4.3 AA |
+| #553 | `e5152f5c` | `.post-meta` contrast in both themes |
+| #554 | `689e42e4` | Event Lineage DAG node marks get a 24×24 px hit target |
+| #556 | `21cf9991` | Citation chip grows to a 24px touch target |
+| #558 | `91dd1bfc` | Bare loading text exposed as live regions |
+| #560 | `59b769e3` | Secondary details/summary toggles sized to `--size-control-min` |
+
+### 3.4 Integration and measurement boundary
+
+| PR | Head | Intent |
+| ---: | --- | --- |
+| #417 | `cb08377c` | TEPP topic-lineage consumption boundary (TRSL-TM + CHRONOS/TDT) ADR |
+| #468 | `228f13dd` | Bind fast-mlsirm, Keyverse, orchestrator, and TEPP integration tests |
+| #258-family measurement note | — | GRM/GPCM/CAT/FIPC parameter recovery (#451–#454) landed earlier; true-parameter RMSE remains the acceptance bar |
+
+### 3.5 Documentation
+
+| PR | Intent |
+| ---: | --- |
+| #565 | Sync AGENTS.md / CLAUDE.md with accepted ADR boundaries |
+| this file | Non-identifying gap baseline refresh (ADR 0001) |
+
+Closed as superseded during this loop: #368 (baseline rewrite superseded by
+this file per §3.5 of the prior snapshot).
+
+## 4. Open issues (complete live queue; product acceptance remaining on `main`)
+
+| Issue | User-visible gap | Active PR |
+| ---: | --- | --- |
+| #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge |
+| #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work |
+| #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack |
+| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | #658; still open and not protected-main evidence |
+| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | #632 preserves internal provenance; public verification acceptance remains open |
+| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #657 consumer lifecycle; executable producer route remains unavailable |
+| #280 | Full project-lifecycle history and handover intervals | #640 adds case/project journeys and #663 adds evidence-backed Project exploration; authoritative lifecycle reconciliation remains #284 |
+| #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed |
+| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | #704 recreates the provider-side contract on current `main` without arbitrary fusion weights; #343 remains only a non-default-stack merge and #355 is a distinct calendar contract |
+| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required |
+
+## 5. Open product and technical gaps
+
+| Gap | Current evidence | Acceptance requirement |
+| --- | --- | --- |
+| Protected release | 12 open PRs at snapshot, all targeting `main` with normal auto-merge enabled. None has the required independent approval, and running checks on #631/#632/#663 are not treated as blockers for safe work on other PRs. #666's merge into the non-default #663 branch is not protected-main delivery | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA |
+| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention |
+| Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior |
+| Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push |
+| Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc |
+| Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence |
+| Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved |
+| Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing |
+| Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts |
+| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility, label-bound, and temporal test-double regressions are repaired. #666's heuristic removal is composed into this parent but is not separately protected-main evidence. #640 separately adds project journeys without claiming authoritative lifecycle status | Combined #663 must pass exact-head checks and independent approval before protected merge. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence |
+| Voice primary history | Protected `main` `bbb19192` includes ADR 0252 / #761 (migration 0243, GiST primary-period exclusion, `clock_timestamp()` after the source-row lock, API/ontology half-open cutoff SQL). v2.22.1 adds synthetic PostgreSQL integration tests for A → B → A at before/between/after cutoffs, concurrent primary updates, additional-assignment close, and 0237→0243 trigger replay. This is not yet protected-main evidence | Land the live-test slice through the protected gate with independent exact-head APPROVE; close #748 only after that protected delivery |
+| Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface |
+| Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding |
+| Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired |
+| SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound |
+| Event Lineage evidence | Channel evidence and Allen relations live on #387 / #484 | Persist channel scores, explain them in the popup, never invent a fused score |
+| Scientific measurement | Durable accepted TEPP receipts and LineageWeave #614's exact accepted snapshot/cutoff/run/pair-count consumer are protected; TEPP #237 remains open, so no registered producer artifact exists yet. #387 removes inferred/default persistence weights, but several older reconstruction tests still pass hand-authored numeric dictionaries that are not estimator evidence | Land TEPP #237 through its protected gate, then replace remaining reconstruction-test constants with provenance-bearing fast-mlsirm estimates over synthetic fixtures. Retain true-parameter RMSE recovery as the acceptance bar |
+| Asynchronous authorization | Protected `main` rebuilds Global Ask worker scope after the bearer token leaves the request; #468 now persists exact Keyverse organization/process-unit scope in 3NF child tables and intersects it with current affiliations | Land #468 through the protected gate; prove a second affiliation and a revoked process unit cannot widen delayed-job evidence |
+| Planned-facility intent | Planned-facility relationship intent remains only on closed, unmerged #490; earlier stack-only merges were not protected delivery | Recreate the evidence-backed slice on a current base and land through protected `main` before a release claim |
+| Accessibility and responsive UX | #602 delivered base post-detail modal semantics; #605 adds selected-post refocus, collapsed/hidden/inert/CSS-invisible focus exclusion across both modal types, readable evidence separators, focused tests, and desktop/mobile Storybook screenshots | Land #605 through the protected gate, then complete screen-reader and authenticated Playwright acceptance on the exact release head |
+| Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release |
+| Frontend delivery performance | #644 implements a native dynamic-import boundary for conditional workspace surfaces and retains accessible loading/error states; exact-head checks passed but the PR is not protected-main evidence | Merge #644 normally, rebuild the protected-main production bundle, and retain the measured chunk inventory rather than raising the warning limit |
+| External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, DiskSage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence |
+| Naruon email/project lineage | #704 provides a strict store-agnostic v1 contract, opaque evidence references, observed/inferred truth separation, knowledge-cutoff admission, and explicit unavailable states. Inferred edges require an injected provenance-bearing fast-mlsirm estimate; no local default weight exists | Merge #704 through protected `main`, publish an immutable attested artifact, then enable the Naruon consumer only against that released version and its contract fixtures |
+| MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there |
+| Accelerator runtime ownership | ADR 0076/0208 already prohibit local model and mathematical ownership; ADR 0237 now defines MLX as a native orchestrator-side service and TEPP/fast-mlsirm CUDA/OpenCL/CPU profiles as scientific-compute-owner deployments, so LineageWeave Compose remains device-neutral. RankWeave remains the dependency-free Python retrieval-fusion/evaluation owner behind its published contract | TEPP and fast-mlsirm must publish deterministic CPU recovery plus conformance evidence for every advertised CUDA/OpenCL profile; contextual-orchestrator must prove native MLX availability through its provider-neutral health/contract boundary. LineageWeave accepts only versioned, provenance-bearing envelopes and fails closed when the owner is unavailable |
+| Product contract authority | The current LineageWeave PRD records exact-case ecosystem authorities. TEPP, fast-mlsirm, keyverse, ThreadWeave, and RankWeave PR #41 have standalone PRDs; RankWeave's remains unmerged. contextual-orchestrator, disksage, and wardnet still rely on product/architecture documents, and naruon has only a scoped Topic Intelligence PRD | Keep ADRs normative, preserve canonical repository case in machine references, land the pending PRDs, and add standalone PRDs in each remaining owning repository before cross-product release claims exceed its documented boundary |
+| Release quality | PR #660 is now on protected `main`; its pre-merge full Python suite passed 1,352 tests with 17 skips, but release-wide frontend, Storybook, security, browser, and runtime acceptance remain unproven on one exact protected head | Repository-wide coverage, docstrings, Storybook, security, browser, and release evidence on one exact head |
+| PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read |
+| Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration |
+
+### 5.1 Closed PR #490 decomposition (issue #611)
+
+Protected `main` at `04e6b610` and the three open PRs present during the initial
+decomposition were rechecked; the later audit snapshot above includes #631
+itself as the fourth open PR. Protected `main` contains none of PR #490. That PR remains
+closed, unmerged branch evidence; its ADR 0133–0137 files are not normative and
+its 321-file tree must not be replayed. Current-main code and schema searches
+give this delivery matrix:
+
+| Closed-branch decision | Current-main classification | Smallest remaining delivery |
+| --- | --- | --- |
+| ADR 0133 source-reference research | Partial foundation: protected `main` has the self-hosted SearXNG relation-verification client and fail-closed configuration, but it verifies an already extracted relation. It has no source-unit/image-region lead, cited-resource retrieval, claim judgment, or normalized research citation workflow | One post-scoped lead-to-citation slice that reuses the self-hosted SearXNG search boundary, adds public-target SSRF/redirect rejection for result retrieval, and judges through contextual-orchestrator with explicit unavailable outcomes |
+| ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states |
+| ADR 0135 kind/status-exact analysis actions | Partial: protected `main` has kind-aware start/retry controls plus normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts; it does not contain the closed branch's unified guidance component or its full kind × status interaction inventory | Test the current run-kind/status matrix first, then add only a proven missing state/control pair rather than copying the closed-branch function |
+| ADR 0136 per-post Ask history | Partial: `post_chat_result` / `post_chat_citation`, the authorized post Chat API, and its linear exchange history are on protected `main`. Account-and-post-scoped sessions, ordered turns, list/select/new controls, and batched citation reauthorization are not | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before adding the conversation picker |
+| ADR 0137 cross-post customer identity | Partial foundation: protected `main` preserves source customer hints and has corporate-catalog unique/miss/tie safeguards, but it has no normalized cross-post customer-identity judgment, supporting-post binding, or corporate-name-history workflow | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint |
+
+This matrix satisfies only #611's current-main inventory step. Issue #611
+remains open: every unmet criterion above still needs a focused regression test
+and exact-head current-main implementation PR before its acceptance criteria
+are satisfied. No stale check, review, or implementation is transferred from
+#490.
+
+## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited)
+
+Each item needs a Storybook scene, an edge-case story, and an automated check
+before a commercial release claim. Figma File ID `1Su3lDRmiZdcUs47t1QwIX`.
+
+| Dimension | Current | Gap |
+| --- | --- | --- |
+| Accessibility | Partial labels/roles on board, popup, login | WCAG 2.2 AA on login, board, popup, Ask, calendar, admin; focus order; live regions |
+| Touch & Interaction | Click-first popup and lists | 44px targets, swipe/escape to dismiss popup, no hover-only actions |
+| Performance | Board caps and hint render limits exist | Interaction-to-next-paint on board search, DAG, Ask; no N+1 (#358) |
+| Style Selection | Korean UI standards merged (#347) | Tokenized light/dark; Anti-Slop-UI density; no decorative noise |
+| Layout & Responsive | Desktop popup shell | 402px-class phone layout; stacked GNB; readable DAG |
+| Typography & Color | Badge tokens extracted | Contrast on badges, links, error/status; no raw hex in components |
+| Animation | Minimal | Reduced-motion; no blocking animation on evidence open |
+| Forms & Feedback | Login, Ask, tickets, admin brand | Inline validation, next-action copy, unavailable vs failed distinction |
+| Navigation Patterns | Board / customers / calendar / Ask / admin | Deep-link post + OIDC return URL (#426); bookmarkable Ask |
+| Charts & Data | Period reports, leftover pairs, Rankings, DAG | Honest empty/unavailable; no invented theta; Storybook chart states |
+
+## 7. Ecosystem leverage order
+
+Reuse before rebuild. Consume these ContextualWisdomLab packages in this order
+of leverage; open connector PRs there when the defect is upstream:
+
+1. **contextual-orchestrator** — every LLM/VISION/embedding call (Fugu / Conductor / TRINITY routing). Never a raw provider SDK.
+2. **Keyverse** — OIDC issuer, JWKS, tenant principals.
+3. **RankWeave** — fused scores and rankings; never invent a fused score or theta.
+4. **TEPP** — calibrated measurement; persist receipts; no local reimplementation.
+5. **fast-mlsirm** — GRM/GPCM/CAT/FIPC recovery tests (#451–#454) must stay true-parameter RMSE.
+6. **ThreadWeave** — tree assembly.
+7. **Naruon** — calendar and email/project lineage projection (#336, #338, #355).
+8. **DiskSage / wardnet** — storage and network policy as needed.
+9. **ContextualWisdomLab/.github** — required review workflows (OpenCode, Strix, Noema) and the LineageWeave hourly caller (#1259). If stacked PRs miss central review or coverage-evidence fails on pnpm 9 (`--trust-lockfile` is pnpm 11.3) or a missing Vitest coverage provider, fix the org workflow (#1258), not a local bypass.
+
+## 8. Public ontology publication boundary
+
+- PR #426 publishes fragment-addressable HTML, byte-identical Turtle,
+ isomorphic JSON-LD and N-Triples, the PROV-O support profile, and a
+ source-digest manifest from the authoritative ontology.
+- Pull requests validate only. Only protected `main` may publish, and the
+ generated-directory marker, linked-IRI, duplicate-fragment, symlink, and
+ source-overlap checks fail closed.
+- The lowercase knowledge-graph namespace and repository-case support-profile
+ namespace remain distinct until issue #372 delivers a versioned migration
+ and compatibility decision; this publication PR rewrites neither identity.
+- Until the protected deployment and exact URL checks succeed, the public
+ ontology endpoint remains unavailable and must not be represented as live.
+
+## 9. Evidence boundaries
+
+- Never add a real record, title, name, identifier, screenshot, log, benchmark
+ artifact, or documentation example to this repository.
+- Attendance or co-occurrence is not responsibility, project, customer, or
+ affiliation evidence. Preserve uncertainty and provenance.
+- Missing transport, model capability, accepted envelope, or persistence is
+ unavailable or failed evidence, never a placeholder result.
+- Local green tests, bot statuses, auto-merge, and warning-only checks do not
+ prove a protected merge.
+- Re-fetch base/head SHAs, checks, review threads, approvals, rulesets, and the
+ merge SHA immediately before any lifecycle claim.
+- Do not self-approve. Independent OpenCode / Strix / Noema review is required.
+- Do not force-push. Do not treat GitHub Checks duration as a blocker; repair
+ the failing check instead.
+- `COPILOT_GITHUB_TOKEN` is not used.
+
+## 10. Next acceptance loop (autonomous merge order)
+
+Process every open PR in ascending number order, considering leverage; for
+each: check reviews → repair → re-verify Checks → merge → continue. Checks and
+review latency are never blockers — keep working while they settle.
+
+1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile
+ open .github#1263, and land the atomic hourly LineageWeave caller in open
+ .github#1288 only through their protected gates.
+2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657,
+ #658, #659, #660, and #663 only after each exact head shows terminal green
+ required checks plus current-head independent approval. Treat #666's
+ non-default-branch merge only as part of #663's combined candidate and
+ collect all protected evidence on #663's exact head.
+3. While hosted checks or independent reviews wait, resume user-visible gaps
+ from §5 in leverage order:
+ external semantic verification (#272), Naruon calendar (#355/#336), and
+ authenticated operations/ontology publication acceptance. Event Lineage
+ evidence shipped in merged PR #387 and closed issue #274 is not an open gap.
+4. Rename remaining `[Buyer Gap]` issue titles to neutral product-object
+ naming per repository convention (no "Buyer" for internal objects).
+5. Keep psychometric tests as true-parameter recovery (RMSE); never fixture
+ tautologies, invented theta, or hand-authored numeric weights. Remove
+ weights from tests that do not exercise fusion; fusion tests must consume
+ provenance-bearing fast-mlsirm estimates over synthetic fixtures.
+6. Run frontend lint/test/build/Storybook, backend tests, and authenticated
+ browser/accessibility checks on the exact candidate release head.
+7. Fix only evidence-backed failures and repeat the protected merge gate.
+8. Refresh this file each loop with the exact queue state.
+
+## 11. Spec pointers (derive, do not fork)
+
+- Product/architecture: `ARCHITECTURE.md`, `AGENTS.md`, `CLAUDE.md`
+- Research grounding: ADR 0084, `docs/lineage-bi-research-notes.md`
+- Demo identity: ADR 0001
+- Figma boundary: ADR 0002 (File ID `1Su3lDRmiZdcUs47t1QwIX`)
+- Orchestrator / paper-grounded models: ADR 0015, ADR 0076 (Fugu, TRINITY, Conductor)
+- Ontology / PROV-O / SKOS: ADR 0004, ADR 0011, issue #372
+- Analysis runs / TEPP: ADR 0013–0023, issue #79 / #277
+- Calendar / Naruon: issues #336 / #338, PR #355, operator consumption v2.17.0
+- Ask Agent: issues #269–#272, #358–#363
+
+Citations in doctoring and ADRs use APA 7th. Do not invent a heuristic where
+the papers leave the decision undecided.
+
+## 12. Delivery snapshot (2026-08-27)
+
+Fresh merges on protected `main`, verified from PR lifecycle state and
+post-merge reruns (not transferable evidence for later heads):
+
+| PR | Delivery | Governing ADR / reference |
+| ---: | --- | --- |
+| #643 | Shared StatusNotice (ADR 0220): success/unavailable/retry states, WorkspaceCalendar auth-unavailable copy, 5-locale i18n; CI Full suite 22m54s green | ADR 0220 |
+| #644 | Native workspace surface split: 9 conditionally rendered components as lazy() dynamic imports behind a SurfaceBoundary error boundary; build emits 9 chunks (1.5-37 kB), main bundle 543 kB; 470 frontend tests, tsc, Storybook green | — |
+| #762 | Evidence-bound project history (ADR 0243): /api/projects/{key}/history endpoint, project_history.py projection, fetchProjectHistory client, standalone ProjectHistoryTimeline component; supersedes #668 (3-way merge kept only the additive +2279/-0, dropping the branch's 8k shared-file reverts; popup UI hookup deferred as a scoped follow-up) | ADR 0243 |
+| #763 | Live-PostgreSQL A→B→A Voice history validation (ADR 0252) proving effective_from/effective_to interval replacement across repeated primary-Voice imports | ADR 0252 |
+| #764 | Test-only coverage lift: observability 78%→96%, post_summary 77%→89%, claim_verification 86%→99%; package line coverage 93.5%→95% (484→371 missing); 1651 Python tests green | — |
+| #761 | Temporal imported-primary Voice history (ADR 0252): migration 0243 (`effective_to` + GiST primary-period exclusion + synchronize trigger), refined 0237 `least()` effective_from backfill, `effective_from/effective_to` dataclass/export + `coalesce($2,$3)` cutoff predicate. Completes the half-shipped main layer that queried `voice.effective_to` against a missing column. CI Full suite 19m13s green | ADR 0252 |
+| #629 | Provider work released before embedding pool bound; landing reads bounded (k6-verified concurrency); merged with strix-only infra timeout (Full suite + all other gates green) | — |
+| #750 | Leftover-map unexplained leftover share persisted (`report_leftover_map_unexplained_share`, share `s = U² / R²`) | ADR 0233 |
+| #749 | Authorized job-family/job-series import snapshots (`0223_authorized_job_architecture`) | ADR 0263 |
+| #759 | ***Promoted** the ONET rating-store stack to `main`: migrations 0222/0223, authenticated rating/rating-sources/rating-occupations endpoints, `OccupationRatingProfile` UI + stories, rating client functions, import scripts, ADR 0252–0263 references. Semgrep SQLi nullified by PL/pgSQL `format(%I/%L)` DDL + documented `nosemgrep`; 1583 Python + 447 frontend tests green | ADR 0257–0263 |
+| #747 | Current product and MCP manuals (`docs/manuals/*`, contract tests) | ADR 0118-family |
+| #754 | Customer-actionable copy and ADR 0237 accelerator runtime boundary; share/bookmark/verification call sites reworded and ko/zh/ja/vi translations completed after review | ADR 0237 |
+| #700 | Source conversation-turn evidence ingestion (`0233_source_conversation_turn_evidence`, choke/adjacency resilience) | ADR 0238 |
+| #658 | Optional Global Ask knowledge cutoff honoring `source_post_revision` cover | ADR 0216 |
+| #632 | Graph-fact source provenance preserved through MCP streaming + verified psql-parity migration fixture | ADR 0166 |
+| #742 | Evidence-bound product-operations relations (stack base) | ADR 0235 |
+| #743 | Imported occupation-rating source catalog (stack base) | ADR 0260 |
+| #745 | Occupation catalog title filter (stack base) | ADR 0262 |
+| #746 | Rating-source occupation selector (stack base) | ADR 0261 |
+| #740 | Occupation rating evidence view (stack base) | ADR 0259 |
+| #720 | Cancel stale test runs on PR close | — |
+| #716 | Prioritized evidence-bound operations backfill | — |
+| #711 | Pinned validated structured-workflow runtime | — |
+| #704 | Current-main external lineage contract publication | — |
+
+The ONET rows stacked into base branches (#743/#745/#746/#740/#732) reached
+`main` together through the #759 promotion; their per-base merge records are
+historical evidence only. The job-architecture artifact ship originally via
+#749 is now re-verified on `main` from the promotion.
diff --git a/docs/evidence/product-technical-gap-baseline-history-through-20260918.md b/docs/evidence/product-technical-gap-baseline-history-through-20260918.md
new file mode 100644
index 000000000..7d9545d29
--- /dev/null
+++ b/docs/evidence/product-technical-gap-baseline-history-through-20260918.md
@@ -0,0 +1,125 @@
+# Product & Technical Gap Baseline
+
+> Current authority snapshot: 2026-09-18.
+>
+> Live protected refs, PRs/Issues, ADRs, exact heads and exact-head receipts remain authoritative. Historical overlays through 2026-09-13 live in [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](product-technical-gap-baseline-history-through-20260913.md).
+
+## Delivery rules
+
+No release is admitted from the current protected head. Parent/head/base movement invalidates descendant acceptance evidence. Ordinary/non-force convergence must preserve every valid product/test/fixture/contract/evidence delta, but validation receipts never transfer across moved heads. Queued, skipped, cancelled, `action_required`, COMMENTED, predecessor-head, dispatcher-only, rate-limited or source-neutral results are not GREEN. A terminal workflow/job `failure` with no runner assignment and zero executed steps is control-plane/pre-execution evidence rather than an executed product/security failure; it still remains fail-closed and non-GREEN.
+
+LineageWeave consumes released canonical-owner contracts/ACLs and does not copy contextual-orchestrator routing/admission, `.github` queue/review policy, fast-mlsirm/TEPP psychometrics, RankWeave ranking, CalendarWeave/Naruon scheduling or other owner implementations. External/model work stays outside long-lived DB transactions/locks; persistence reacquires the shortest necessary lease, revalidates state and uses idempotent/UPSERT semantics where required.
+
+Material UI acceptance requires current-head rendered buyer evidence as well as repository checks: normal/loading/empty/error/permission/responsive states, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable performance evidence.
+
+## Current foundations
+
+### Customer Master / shared catalog
+
+#1079 exact `c2923950e73c88a9f9fd932332ddd47682da124b` remains the Customer Master/shared-catalog authorization candidate. Product Tests/SAST/Security are GREEN; required CodeQL remains RED on repository-baseline owner findings outside #1079's authorization delta. #1077/#1080 retain separate connection-lease/TOCTOU responsibility. No provider/model execution belongs in Customer Master transactions.
+
+### Governed translation delivery
+
+#929 exact `d4f42f579663e88a0c9af0cc492aa6ff7cae96ee` owns the concrete Customer Master eight-locale review candidate. The original RED `eb6eca97df64656ab0bce1e5d3deeaa7c5566760` still requires the exact 37 governed keys across `ko/en/ja/zh/vi/es/de/fr`, 296 nonblank localized values, placeholder parity, no non-English source fallback, replay idempotency, publication completeness and rollback safety; migration 0248 deliberately leaves version 1 in `draft`.
+
+Data-ownership RED `ed23e14b49a7bcef1bcd124e5eb744fb7adb9a86` reproduces the predecessor defect where an already-existing `lineageweave/customer-master` v1 draft could be adopted, overwritten and later deleted by 0248 rollback. The ownership repair establishes `migrations/0247_z_customer_master_translation_seed_ownership.sql` before 0248 with migration-scoped ownership and exact per-file `lineageweave.migration_file` provenance from `docker/postgres-init/migrate.sh`. `pending`, `owned`, and `blocked` distinguish a first-run reservation, a successfully materialized seed, and a pre-existing operator resource. Exact forward 0248 provenance may create a pending target or replay an owned seed but explicitly refuses a blocked target; child ownership checks are scoped to that forward migration so an operator-owned draft remains normally editable. `rollback/0248_customer_master_translation_draft.sql` stamps transaction-local rollback provenance, and only that rollback context requires the root target to be owned before deletion.
+
+Ownership TEMP-shadow RED `2b7951a0384add445b4c2086337397772dc008e5` covers caller-created `pg_temp.ui_translation_seed_ownership` spoofing the migration-ownership trigger functions. Repair `92cf139fac69729387e6e3dc744658b9355160d1` pins all three ownership functions to `SET search_path = pg_catalog, public, pg_temp`; `tests/test_customer_master_translation_seed_ownership.py` preserves that real-PostgreSQL regression alongside ordering/provenance, ordinary operator lifecycle, byte-preserving unowned refusal, owned replay/rollback and empty-reservation cleanup.
+
+Fresh review identified the same permanent-vs-TEMP relation-resolution defect in the pre-existing translation-ledger integrity functions. RED `0ea88968ff13b6b5003904a8bc306f5164b4f65b` adds three real-PostgreSQL adversarial paths: TEMP `ui_translation_key`/`ui_translation_text` must not make incomplete permanent copy publishable; TEMP `ui_translation_resource` reporting `draft` must not make published permanent child rows mutable; and a TEMP root must not let `TRUNCATE public.ui_translation_text` bypass immutable published-copy evidence. Causal repairs `ff1084ba6eb6ff02f17745ea1e6fb3abc77895f9` and `ac60da45aa12d8b85a2f4b45a63ce7df4e4cd539` pin `guard_ui_translation_resource_mutation()`, `guard_ui_translation_child_mutation()` and `guard_ui_translation_truncate()` to `pg_catalog, public, pg_temp`. No privilege elevation, source copy or alternate publication authority is introduced.
+
+Replay-concurrency RED `45f11ea2d730e5bb701e045d2c27599d789cde96` adds a real-PostgreSQL overlap where one transaction holds an uncommitted migration-key reservation while a second replay reaches the ownership initializer. Repair `4fdb2945d15fb849bf12143ea3caa4785af1301e` uses `ON CONFLICT (migration_key) DO NOTHING` as the unique-index serialization point, then locks and validates the committed ownership row before locking the product resource. Identity drift, blocked/unowned adoption, pending/resource collision and owned replay remain fail-closed/idempotent; the lock order is ownership then product resource.
+
+A second concurrency RED `1becd50316d9beef74d647975fc2380c23a517f5` covers the next stage of replay: two actual 0248 seed transactions can both observe no Customer Master root before either creates it. The ownership trigger serializes those inserts, but the predecessor loser resumed with a plain root INSERT and could fail on the aggregate unique constraint after the winner committed. Repair `cb3d42629c30225cb2dec452c4de7100322fa72f` makes the root INSERT conflict-idempotent, then re-reads the committed resource under `FOR UPDATE` and continues only when `ui_translation_seed_ownership` proves that exact resource is `owned` by migration 0248. An external/unowned collision remains fail-closed; ownership → product-resource lock order is preserved.
+
+Review-preservation RED `f467cae651df5db6dca18f25e460d20c84701675` covers the lifecycle after successful seeding: a legitimate language/product review edit to the migration-owned draft must not be overwritten by a later replay of historical 0248, and a reviewed immutable publication must not be rejected by startup merely because reviewed copy differs from the original seed bytes. Repair `4630664e6841774b4c88f4dae9d9858136453f2b` adds `0247_zz_customer_master_translation_seed_replay_guard.sql` before 0248; during exact 0248 provenance its `BEFORE UPDATE` trigger suppresses only conflict-updates against the exact 0248-owned Customer Master v1 resource, preserving direct draft replay while leaving missing inserts, unowned fail-closed behavior and ordinary review edits intact. Follow-up `4337d7222f3373231ec737b574d46b85bfb1fa48` fixes the published/startup path at the canonical migration runner: once the exact 0248 ownership tuple is committed `owned`, the historical candidate seed is purpose-complete and is skipped on later startup. `pending` and `blocked` ownership still execute 0248, preserving first-run/concurrency/unowned failure semantics. Test alignment `c40170b274083623bfeadec8693ed8998036d600` statically requires that owned-seed admission occur before generic migration application, retains a real-PostgreSQL direct-draft replay check, and models startup preservation of reviewed immutable publication.
+
+Completed-seed retirement RED `0c034937d95ef2c4dfcf433f30bc7305654d5962` covers a later authority-revival defect. In the predecessor, ordinary operator deletion of a successfully `owned` review candidate cascaded through the ownership FK, erased the completion record, and let the next startup recreate a `pending` reservation and historical 0248 copy. Repair `45d7a5eb73e573400c0b64203b1775964264a23f` adds a purpose-complete `retired` ownership state with `resource_id = NULL`. On ordinary deletion of the exact owned root, the BEFORE DELETE ownership guard detaches the FK and records `retired`, so product deletion can complete without restoring historical seed authority; the runner skips 0248 for `owned|retired`. Deliberate 0248 rollback still requires an exact owned resource and may cascade-remove its ownership row, while explicit ownership-boundary rollback may remove a retired receipt only after the Customer Master v1 product resource is absent. A pre-existing `blocked` operator resource is not a completed seed and does not acquire retired semantics merely by being deleted.
+
+Upgrade RED `c52e7bacf6bc5ef066fa4245e5fdcfa2b8905a6a` models an installation that already has predecessor ownership checks under the current canonical names but without `retired`. Repair `ca11b270211bc6a3d6d829f8f6dfaf9d0dc7a6fc` replaces those stale same-named checks so owned→retired deletion works and later replay remains idempotent.
+
+Non-destructive-upgrade RED `db5435def512615902372a9fc95770bc8c2b3a2b` then proves that the predecessor stale-check loop was too broad: any non-canonical CHECK whose definition mentioned `ownership_state` could be dropped, including independently managed DBA/operator constraints. Repair `4b6d21c629b203bd3a7c36bbbbc943775b9a8f21` limits stale removal to the two known autogenerated predecessor names `ui_translation_seed_ownership_ownership_state_check` and `ui_translation_seed_ownership_check`, preserving `operator_ownership_state_nonempty_ck` across upgrade and replay.
+
+Semantic-upgrade RED `8b395738d2815ee002c85b27648841a06aa5e45f` closes the remaining version-detection hole: a canonical shape CHECK can already contain the token `retired` while still encoding the wrong invariant (`retired` with non-null `resource_id`). The predecessor's `position('retired' in pg_get_constraintdef(...))` therefore mistook malformed partial upgrades for the canonical retirement contract. Causal repair `667aca9b233f269d868fb99f8740aa66002b09ce` assigns explicit catalog-comment version markers to the two repository-owned canonical constraints and replaces any unversioned same-named predecessor exactly once, independent of incidental definition text. Differently named operator constraints remain untouched. Exact test-alignment head `d4f42f579663e88a0c9af0cc492aa6ff7cae96ee` verifies the markers, exercises the malformed-partial-upgrade retirement path, and requires canonical constraint OIDs to remain unchanged after replay so subsequent startup is metadata-only rather than repeated table-lock/validation churn.
+
+#929 remains Ready-for-validation only. Fresh exact-head Tests `35236145547`, Security `35236145569`, Ontology Pages `35236145593`, PROV-O `35236145577`, SAST `35236145534`, and CodeQL `35236145624` exist on `d4f42f579...`. Tests jobs `105252445377` (Full suite/PostgreSQL) and `105252445197` (Frontend) are queued with `runner_id=0` and `steps=[]`; PROV-O is pending. No queued/pending/skipped/predecessor receipt is GREEN and no qualifying current-head independent approval exists. The migration-ownership/replay thread remains open pending hosted exact-head GREEN.
+
+Direct consumer #932 has been ordinarily/non-force two-parent converged to `fb2422537216a19280860f710b55f4df963902db` on parent #929 `d4f42f579...` and remains Draft. The convergence preserves the existing consumer tree while inheriting review preservation, purpose-complete replay admission, seed retirement, non-destructive upgrade and versioned canonical constraint repair through ancestry only; it does not copy ledger truth into frontend source. Exact-head Tests `35236229290` is terminal `skipped` by Draft admission and is not GREEN. Product-wide locale admission remains the currently complete `ko/en/ja/zh/vi` set; the eight-locale Customer Master ledger is a separate publication contract. The publication thread remains unresolved because a complete, safely owned, non-resurrecting and upgrade-safe draft is not qualifying language/product review, immutable publication, hosted PostgreSQL GREEN, or authenticated browser evidence.
+
+### Commercial PostgreSQL tooling
+
+#911 exact `6030b295aadc3ee76dc4d27f5713273f35888325` has Tests/PROV-O/Ontology/SAST GREEN. Security remains fail-closed at canonical Dependency Review availability. Canonical CodeQL producer `.github` run `35042611369` is terminal FAILURE rather than queued: it surfaced repository-baseline Python TLS/ReDoS findings and four JavaScript `js/incomplete-multi-character-sanitization` findings outside the pg8000/libpq delta. #911 stays source-stable and must consume those repairs through their existing owners (#974 and #983) rather than copy them; protected-owner integration followed by fresh #911 validation is required.
+
+### Contextual-orchestrator ownership boundary
+
+#899 exact `a2da5875525cd0950999487ff8fe7d439284dbd2` keeps ADR 0300 `Proposed`. Direct/current descendants remain #902 `9487e029...`, #915 `e2a00383...`, #919 `d78390c5...`, and #966 `f93715af...`; Draft-skipped Tests are not product GREEN. Numerical IRT remains in fast-mlsirm, temporal/multilevel measurement in TEPP, and provider/judge execution in contextual-orchestrator.
+
+### CodeQL baseline / frontend coverage
+
+#974 current exact `4341080f6027d869acb08896e41d761c3f3b8e77` owns the Python CodeQL findings. The linear chat-punctuation/ReDoS repair remains on ancestry. TLS source repair `ff2bcba3c85853da67acf90680e7927a5c9c83e7` builds the certifi-backed context inside `_build_ssl_context()` and applies `minimum_version = TLSv1_2` before return so the floor is explicit before escape while hostname/certificate verification remains intact. Hosted predecessor Tests `35243765633` has now executed: Frontend `105278564382` is SUCCESS through lint/test/build/Storybook, while Full suite/PostgreSQL `105278564710` is FAILURE with exactly **1778 passed, 147 skipped, 1 failed**. The sole failure is the stale `test_http_client_declares_tls_1_2_floor_in_owned_transport_boundary`, which still required the obsolete source text `_SSL_CONTEXT.minimum_version = ssl.TLSVersion.TLSv1_2` and therefore rejected the intentional builder-local CodeQL repair even though runtime TLS semantics were preserved. Exact repair `4341080f...` replaces that implementation-shape assertion with a behavioral boundary contract: a stub context begins at `MINIMUM_SUPPORTED`, `_build_ssl_context()` must return the same object with `minimum_version == TLSv1_2`, and the live `_SSL_CONTEXT` remains >= TLS 1.2. Predecessor SAST `35243765715` is SUCCESS; predecessor CodeQL/Security receipts do not transfer. Fresh exact-head Tests `35267030859`, SAST `35267030789`, CodeQL `35267030868`, and Security `35267030604` have materialized and remain queued/pending, so no new-head GREEN is claimed. Independent protected-state producer `.github` run `35152871013` still serves only as older baseline evidence for `py/insecure-protocol`/`py/polynomial-redos`, not acceptance. Direct Draft child #979 is ordinarily/non-force two-parent converged to `2dfd21110813f474d3068796d0733d96f28d6061` on this exact parent and inherits no receipt.
+
+#983 exact `f48afbe373cdb6aa64abf0f7c4e69e897f820cd8` owns post-body parsing plus LineageWeave frontend coverage closure. Its quote-aware linear `replaceHtmlLikeTags` scanner removes the predecessor multi-character deletion pattern while preserving quoted-attribute tag parsing and ` ` semantic boundaries; this is the owner path, not a reason to exempt CodeQL. Causal quoted-attribute ` ` repair remains `4800c818...`; preserved artifact `10449646541` measured 96.91% lines, 95.14% statements, 95.54% functions and 86.50% branches. Test-only slices `816423c4...`, `e5104121...`, `6519c8e3...`, and `f48afbe...` exercise measured branches without production/gate changes. Independent #1115 producer run `35152871013` executed JavaScript/TypeScript job `105039317150` and preserved artifact `codeql-dispatch-javascript-typescript-35152871013-1` (`sha256:20ce684ed02b6fac40f70e432f10cb929d740016ebf9379c2b95c9b4cda8e5cb`) with four `js/incomplete-multi-character-sanitization` findings at `frontend/src/postBodyDisplay.ts` lines 33, 243, 246 and 337; owner evidence is #983 comment `5718848502`. That protected-baseline evidence does not validate the current repair. Exact-head Tests `35130878136` is terminal **cancelled before runner assignment**: Frontend `104911285691` and Full suite `104911285836` both have `runner_id=0` and `steps=[]`. SAST `35130877960` is SUCCESS. Security `35130878012` is terminal FAILURE only at dependency-review support check `104987987170`; Trivy `104987987025`, Scorecard `104987987073`, and OSV `104987987113` are SUCCESS. CodeQL PR `35130878009` is terminal FAILURE in compatibility/verdict settlement: detection succeeded, compatibility jobs failed while reading/enforcing the current-head dispatch verdict, and dispatch job `105043511749` succeeded. None of that proves the four current-head owner findings absent, so the product review thread remains unresolved; evidence reply is `4040347398`. Descendants #984/#985/#992 inherit no acceptance receipt.
+
+#977 exact `b041ab7dfe5cea09071cdf5d36de2acafb7ae27b` repairs the buyer-visible LeftoverPairList accessibility lane on current serialized parent #830 `bebd77c03e5beae469f42361c20bccc80787ebb5`. Ordinary two-parent reconstruction anchor `41c050fc...` preserves the historical #977 delta while adopting exact #830; product repair `8d78f225...` makes the accessible name start with the exact rendered localized label, mirrors only already-admitted finite persisted evidence (`R`, `Y/E`, rank, `U`, shares, `R̂`, `ξ/ζ`, `d`), and closes the old-payload path so non-finite residual/distance never leak `R —` or `d NaN`. `ae071b203...` adds executable Storybook visible-label/name parity, Tab focus order and Enter selection identity. Dense/mobile RED `a73b7e8...` adds a `mobile1` Storybook path that requires both evidence-heavy actions to fit their own client width, preserve a >=44px target and select the exact farthest pair by pointer/click. Scoped repair `b586ea94...` adds `.leftover-pair-action` wrapping, tokenized minimum target and shrinkable/overflow-wrapping children; `b041ab7d...` activates that class only for LeftoverPairList actions rather than changing the shared `.post-list-item` contract. Fresh exact-head Tests `35283791337` has Frontend `105411486745` and Full suite `105411487122` queued pre-runner, so the new Storybook contract and responsive repair are not hosted GREEN; Security/CodeQL settlement and qualifying independent approval also remain outstanding.
+
+### Embedded-image structural extraction
+
+#1115 exact `6545b5ff7ed88d98daad74ca3ba8f8606dad3fc4` retains structural `HTMLParser` extraction, narrow data-URI allowlist, strict base64 validation, remote-image rejection and LF-correct provenance positioning. Tests `35065642195`, SAST `35065642221`, and Security `35065642147` are GREEN. Consumer CodeQL `35065642188` is terminal FAILURE in compatibility/verdict settlement; dispatch job `104906720511` successfully bound canonical `.github` producer run `35152871013` to the exact PR/head/base. That producer has now fully left runner admission: `validate-dispatch` `104985222128` is SUCCESS; actions job `105039317121` passed analysis and the Medium+ SARIF gate and failed only at `Wake exact CodeQL required job`; Python job `105039317130` produced the two #974-owned baseline findings and artifact digest `sha256:d5ed4802bffeed9a58bdc7aa599b6fe31f81d5e803d14e8952e66f830ba5114c`; JavaScript/TypeScript job `105039317150` produced the four #983-owned baseline findings and artifact digest `sha256:20ce684ed02b6fac40f70e432f10cb929d740016ebf9379c2b95c9b4cda8e5cb`. None of those findings is in #1115's two-file image parser delta, but they are real CodeQL RED and require owner repair integration plus fresh exact-head settlement rather than an exemption. Canonical owner evidence is `.github#1929` comment `5718850188`. OpenCode also submitted `CHANGES_REQUESTED` on the exact head after its coverage gate failed while explicitly reporting no source-backed product finding; this is not an APPROVED review. Current canonical `.github/main@64aa08d7fa487deacd41c761c36277ca68cab6c9` is protected and signature-valid. Merge #2213 adds queued-job evidence and explicit `terminal_pre_execution_failure` classification for no-runner/no-step failures; it improves owner diagnosis but does not retroactively validate #974/#983/#929 or the #1115 producer result. No qualifying current-head approval exists.
+
+## Leftover-map report/comparison stack
+
+### σ/share foundation
+
+The hosted predecessor #874 RED was six stale source-text assertions, not a product regression. The valid contract is four-state empty/share/σ/σ+share with neither field derived from the other. The predecessor #873 Tests `35150049852` later left runner admission: Full suite `104975772740` completed SUCCESS, while Frontend `104975772417` failed at `Test with coverage`; build/Storybook were skipped after that failure. Therefore the earlier pre-runner diagnosis for that predecessor run is historical only.
+
+Current #873 exact `262700d3936d7e783817f4c6fd008afe119d0b23` is test-only. It adds `frontend/src/leftoverMapPlotAxisSingular.test.ts` (blob `c766dc99d4db9882fdeba0d3f9b3cc94fd44809a`) to execute report/comparison tick empty, σ-only, share-only, σ+share and invalid persisted-value fail-closed branches. Production code, coverage denominator/threshold and owner boundaries are unchanged. Exact-head Tests `35176068027` is queued; Frontend `105057942668` and Full suite `105057942759` remain pre-runner with `runner_id=0`, empty runner identity and `steps=[]`. The three remaining inline threads on #873 were outdated informational observations and are now resolved without source changes. Current queue evidence is maintained in canonical Actions owner `.github#712` comment `5706253600`.
+
+The new test delta has been preserved through ordinary two-parent/non-force convergence, not by tree-discarding merge metadata:
+
+- #873 `262700d3936d7e783817f4c6fd008afe119d0b23` -> #874 `3a191487420fd9d06b4fb35fef5d407e078f152a` (Tests `35179432486` queued).
+- #874 `3a191487...` -> #875 `1ac7ddd0637a126c59d0102dcd75a051b059e9f4` (Tests `35179782014` queued).
+- #875 `1ac7ddd0...` -> #876 `4be3c382ce18ce6be272efbcdedfdaa66dc334ff` (Tests `35179807983` queued).
+- #875 `1ac7ddd0...` -> sibling #877 `edcf5baa051046be448a0b356d01c3543b69408a` (Tests `35180148203` queued).
+- #876 `4be3c382...` -> #1033 `38967642e1efbd299dfcd68514c289716edfb597` (Tests `35180490196` queued).
+- #1033 `38967642...` -> #1034 `825f47a268c5c31fecaef3537c24b78511823f4d` (Tests `35180509845` queued).
+
+Each convergence tree explicitly carries blob `c766dc99...` at `frontend/src/leftoverMapPlotAxisSingular.test.ts`. No moved-head Tests receipt is GREEN yet.
+
+### Marker identity and i18n
+
+#876 `4be3c382...` retains report criterion ζ from persisted finite item-axis pairs only. #1033 `38967642...` retains comparison criterion ζ on the same item-coordinate boundary with distinct comparison identity. #1034 `825f47a2...` retains comparison post ξ from persisted finite person-axis pairs only: an unplaceable marker is omitted rather than assigned invented geometry, while the pair-button open path remains available. Existing React/Vitest accessibility evidence (`449a0aa4...` -> `e2b6724b...`) exercises Korean final `aria-label` composition, fail-closed plot omission and surviving pair-button action; that evidence is preserved in the moved #1034 tree, but hosted current-head GREEN and review-thread resolution are still required.
+
+Sibling #877 `edcf5baa...` retains formatted-zero origin identity plus independent share/σ composition. Single-writer commit `d08dafb8...` changed only `frontend/src/i18n.ts`, +32/-0, adding eight regular/origin templates to each ko/zh/ja/vi catalog with placeholders preserved. Writer run `35093668549` / job `104785690763` completed SUCCESS. The later parent-convergence commit preserves both this i18n delta and the #873 test blob. Historical #877 receipts (`35151334447` cancelled; `35135308646` action_required/jobs=0) do not transfer.
+
+Historical #878/#879 remain open evidence carriers until complete verified successor inheritance is proven; their authority points to current #1033 `38967642...` / #1034 `825f47a2...`. No historical tree is replayed wholesale over repaired ancestry.
+
+## Warning / operability ownership
+
+Warnings are repaired at existing owners, not filtered:
+
+- OpenTelemetry `LoggingHandler` deprecation: #1036 / PR #973.
+- PROV-O explicit-migration transaction warnings: #1035.
+- person-projection migration transaction warnings: #1038 / PR #1040 `4d74c32a...`.
+- PostgreSQL Alpine locale and initdb local-auth warnings: #1037 / PR #1039; initdb evidence comment `5695341589`.
+
+Expected PostgreSQL constraint-violation `ERROR` records from negative contract tests are intentional and are not warning-cleanliness defects.
+
+## Buyer-visible gap register
+
+| Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required |
+| --- | --- | --- | --- |
+| Shared-catalog authorization | #1079 `c2923950...` | Product Tests/SAST/Security GREEN; canonical CodeQL owner RED outside authorization delta. | Owner repair integration, fresh CodeQL/model-review settlement, qualifying approval, normal protected merge. |
+| Commercial PostgreSQL tooling | #911 `6030b295...` | Tests/PROV-O/Ontology/SAST GREEN; Dependency Review fail-closed. Canonical CodeQL producer is terminal RED on Python baseline findings owned by #974 and four post-body JS findings owned by #983, not on the pg8000 delta. | Integrate verified owner repairs, fresh #911 Security/CodeQL against protected state, approval. |
+| CO ownership decision lifecycle | #899 `a2da5875...` | ADR 0300 Proposed; #902/#915/#919/#966 preserved; Draft Tests skipped. | Prerequisite integration, fresh required evidence, approval, then Accepted. |
+| Ask HTTP/chat security baseline | #974 `4341080f...` -> #979 `2dfd2111...` | Source-level ReDoS/TLS repairs are present. Hosted predecessor Tests executed: Frontend GREEN; Full suite 1778 passed/147 skipped/1 failed solely on a stale source-shape TLS assertion. `4341080f...` replaces that assertion with behavioral builder-floor evidence; fresh Tests/SAST/Security/CodeQL are queued/pending. | Fresh exact-head Tests/SAST/Security GREEN, producer/consumer CodeQL settlement proving both Python findings absent, independent approval, normal protected integration. |
+| Post-body parser / frontend 100% evidence | #983 `f48afbe...` | Quote-aware linear tag scanner owns the JS sanitizer path; independent #1115 producer confirms four baseline findings in `postBodyDisplay.ts`. Current SAST is GREEN; Tests are terminal cancelled before runner assignment; Security is fail-closed only at Dependency Review support; CodeQL compatibility/verdict settlement failed while current-head dispatch succeeded. | Fresh exact-head producer proving the four findings absent, executed full/coverage/rendered/security GREEN, review resolution, approval. |
+| Leftover-pair action accessibility | #830 `bebd77c...` -> #977 `b041ab7d...` | Accessible-name repair `8d78f225...` is preserved on exact #830. Storybook now covers visible-label-prefix names, finite evidence parity, Tab/Enter focus/selection plus `mobile1` dense overflow, >=44px target and pointer/click identity. Scoped `.leftover-pair-action` wrapping avoids a global post-list style change. Fresh Tests `35283791337` has Frontend `105411486745` and Full suite `105411487122` queued pre-runner. | Executed exact-head frontend/full-suite and Storybook/browser GREEN, Security/CodeQL settlement, translation-ledger consumer convergence, qualifying approval, prerequisite-first integration. |
+| Embedded-image ingestion | #1115 `6545b5ff...` | Tests/SAST/Security GREEN. Canonical producer executed: Python and JS scans are terminal RED only on #974/#983-owned repository-baseline findings outside the two-file image parser delta; actions analysis/SARIF gate passed but consumer wake failed. OpenCode is CHANGES_REQUESTED from a failed coverage gate with no source-backed finding. | Verified owner repair integration, fresh exact-head CodeQL consumer/producer settlement, accepting coverage/review gate, qualifying approval. |
+| Singular/share tick foundation | #873 `262700d...` -> #874 `3a191487...` -> #875 `1ac7ddd0...` | Test-only branch-coverage delta is preserved through non-force convergence; all moved-head Tests are queued; #873 stale informational threads are resolved. | Exact-head coverage/full/build/Storybook/rendered/a11y/security/performance evidence and review; no predecessor transfer. |
+| Report/comparison marker identity | #876 `4be3c382...` -> #1033 `38967642...` -> #1034 `825f47a2...` | ζ/ζ/ξ boundaries and executable localized/fail-closed a11y evidence are preserved; moved-head Tests queued. | Current-head GREEN, remaining review-thread resolution, parent-first rendered/security evidence and qualifying approval. |
+| Comparison origin/a11y identity | #877 `edcf5baa...` | 32-entry ko/zh/ja/vi repair and #873 test blob both preserved; moved-head Tests queued. | Full/rendered/a11y/security evidence and approval. |
+| Warning-clean acceptance | #1036/#973; #1035; #1038/#1040; #1037/#1039 | Existing owner lanes retain deprecation/transaction/locale/initdb findings. | Normal integration and warning-free protected evidence; no suppression. |
+| Catalog connection leases / TOCTOU | #1077 / #1080 | Separate owner lanes; no long DB lease across external/model work. | Causal RED->GREEN, short-transaction evidence, protected integration. |
+| Governed translation delivery | #929 `d4f42f57...` -> #932 `fb242253...` | 37×8 Customer Master draft remains unpublished. Ownership/TEMP-shadow/concurrency/review-preservation/retirement repairs remain present. Non-destructive RED `db5435de...` / repair `4b6d21c...` preserves operator-owned constraints; semantic RED `8b395738...` / repair `667aca9b...` replaces unversioned same-named canonical checks independent of incidental `retired` text and `d4f42f57...` pins marker/OID-stable replay. #929 Tests `35236145547` has Full/PostgreSQL `105252445377` and Frontend `105252445197` queued pre-runner; #932 Tests `35236229290` is Draft-skipped. | Exact-head hosted PostgreSQL/full-suite GREEN, ownership/replay review resolution, fresh current-head review, independent language/product review, immutable publication, authenticated API/browser eight-locale evidence, state/responsive/keyboard/focus/screen-reader/CJK checks, Security/SAST/CodeQL and qualifying approval. |
+| MCP buyer-path latency | #1009 | Target p95 <= 20 ms where applicable. | Representative cold/authenticated measurements and causal profiling; Rust-first repair when warranted. |
+| Release identity / immutable publication | #961 / #1056 | Protected main is not release-ready. | One protected SHA with version/CHANGELOG/tag/package/immutable release, SBOM/provenance, reproducibility and rollback evidence. |
diff --git a/docs/product-requirements.md b/docs/product-requirements.md
index a8b741521..2f0991b61 100644
--- a/docs/product-requirements.md
+++ b/docs/product-requirements.md
@@ -526,7 +526,7 @@ current boundary until that repository adopts one.
| `ContextualWisdomLab/keyverse` | `docs/PRD.md` | Production OIDC/JWKS/identity control plane; local demo Keycloak is not Keyverse |
| `ContextualWisdomLab/RankWeave` | No standalone PRD; `README.md`, `ARCHITECTURE.md` | Store-agnostic ranking/fusion dependency; caller owns channels and authorization |
| `ContextualWisdomLab/ThreadWeave` | `docs/PRD.md` | Deterministic reference-thread assembly dependency; LineageWeave owns records and persistence |
-| `ContextualWisdomLab/DiskSage` | No standalone PRD; `docs/superpowers/specs/2026-07-10-disksage-design.md` | Prospective storage-policy boundary; no current runtime integration |
+| `ContextualWisdomLab/disksage` | No standalone PRD; `docs/superpowers/specs/2026-07-10-disksage-design.md` | Prospective storage-policy boundary; no current runtime integration |
| `ContextualWisdomLab/wardnet` | No standalone PRD; `README.md`, `docs/architecture.md` | Prospective gateway/network-policy boundary; no current runtime integration |
| `ContextualWisdomLab/naruon` | Scoped `docs/topic-intelligence/PRD.md` only | Owns observed calendar/email projections; LineageWeave owns commitments and combined display |
| `ContextualWisdomLab/LineageWeave` | This PRD, with ADRs normative | Evidence BI/orchestration, lineage, semantic projection, API, and UI owner |
diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md
index 7ff09f08e..02d1441e0 100644
--- a/docs/product-technical-gap-baseline.md
+++ b/docs/product-technical-gap-baseline.md
@@ -1,1389 +1,148 @@
# Product & Technical Gap Baseline
-> Current serialized repair (2026-09-07): #829 consumes exact promoted #828 `7b6dbbb99a09d0523bce43c6872bbd9fa382a43a` and preserves persisted `U²/R²` comparison presentation as ADR 0369 / v2.55.0. Finite values are present in the actionable button name and visible badge; missing/non-finite values are absent; values are never derived/clamped; current-parent whole-population authorization remains intact. Historical ADR0295/v2.52.0 is evidence only. Inline five-locale copy is compatibility presentation while #922/#929/#932 remain the eight-locale translation-ledger owner path.
+> Exact-head refresh: 2026-09-21 13:48 KST. Protected `main` remains
+> `83eba56149eb802cd63642c507c324c9976ec78e`. Aggregate open-PR/issue counts
+> describe queue size rather than delivery. The current authentication delivery
+> gap tracked by #1119 is no longer source-level public-client ROPC: current #1120
+> source carries distinct confidential viewer/admin integration actors and disables
+> public browser direct grants in the same causal migration. Rendered Authorization
+> Code + S256 PKCE/session/return-path/permission acceptance, authenticated
+> PostgreSQL evidence, protected exact-head Checks, independent approval, merge,
+> and release remain unavailable.
+> Current mutable authority overlay: 2026-09-21. Historical implementation detail belongs in Git/PR history. A predecessor, sibling, descendant, focused harness, skipped workflow, queued workflow, cancelled workflow, or documentation-only workflow is not acceptance for a moved product head.
-> Current serialized repair (2026-09-07): #828 is reconstructed from exact #827 `0f9e9c8db37948041f39b4e68e4bbd808fa83752` as ADR 0367 / v2.54.0. The valid delta carries persisted grouping-comparison `leftover_map_axes` but exposes them only when the caller can see the entire persisted grouping population; partial visibility returns no aggregate and never recomputes psychometrics from the visible subset. Presentation consumes persisted `leftover_share` only, with zero and finite negative values explicit and missing/non-finite values omitted. Historical v2.50.0/ADR0293 identity is evidence only. Existing five-locale compatibility copy is preserved while the database-backed eight-locale translation-ledger authority remains #922/#929/#932; this Draft does not create a competing translation source.
+> Accessibility source ownership is serialized in #977. The last source-bearing
+> accessibility repair before this documentation refresh is
+> `bce09c145b979e348d3db3ecad01246ff2d20ed9`; the live PR API/body owns #977's
+> exact current head because writing this baseline necessarily creates another
+> commit. #1041 is merged documentation history, not a second `LeftoverPairList`
+> source writer. Completed successful protected receipts on the unchanged live
+> product-owner head are authoritative for acceptance; queued, skipped, cancelled,
+> failed, runnerless, documentation-only, or predecessor receipts are non-accepting
+> and do not transfer.
+## Delivery authority
-> 2026-09-07 #822 reconstruction: exact #821 `93eaa40f...` owns ADR 0290/v2.47.0 and the full-visible-grouping coverage boundary. Preserve historical item-coverage composition as ADR 0291/v2.48.0; partial-visibility rows omit the shared persisted coverage aggregate. #963 remains owner of broader current-vs-historical baseline governance.
-> #821 current-parent reconstruction: preserve grouping-comparison leftover-map post complete-case coverage from historical `11a78553...` on exact #820 `503d043e...`, but move the decision to ADR 0290 / v2.47.0 and fail closed persisted coverage whenever ABAC hides any grouping member. Review 5126637582 is the authorization RED authority; #963 still owns the broader current-vs-historical baseline cleanup.
-> #820 exact-current-parent reconstruction: persisted singular-value axis badges
-> are reconstructed from #819 `f37ca315e3c48fa37bbcafe96e46c5d7dab991b7`.
-> Preserve finite, non-negative persisted `σ_k`, including rank-0 `σ 0.00`; omit missing,
-> non-finite, or negative singular values independently of axis share. Parent share-only
-> regressions run with singular value unavailable so the contracts remain orthogonal.
-> ADR 0289 stays Proposed while Draft; package/frontend/runtime identity is 2.46.0.
+- Protected `main`, live PR heads/bases, `AGENTS.md` / `CLAUDE.md`, ADRs, PRD/TRD, and exact workflow receipts are authoritative.
+- LineageWeave owns lineage/evidence/customer-master/composition/read-model behavior. Canonical-owner source is consumed only through released/versioned contracts; it is not copied here.
+- Draft/skipped, queued, cancelled, `action_required`, runnerless, review-skipped, or owner-control-plane receipts are not product GREEN.
+- Parent movement requires ordinary non-force descendant convergence, reconstruction, or safe retargeting. Closed intermediate branches must not remain live ancestry after verified normal merge into an active parent.
+- Force push, destructive rebase, self-approval, gate weakening, synthetic status, blind rerun, and no-op wake commits are not acceptance tools.
+- Release readiness requires one exact protected candidate with version/CHANGELOG/package/tag/release/SBOM/provenance/reproducibility/rollback evidence.
-> #819 current-parent reconstruction: v2.45 pair-list post coverage fail-close
-> is being rebuilt from exact #818 `bc971a402ef9faecb2f0b4ffd743092f4779d76b`.
-> Preserve only feature delta `a2c965511d26923bd878ec56d655fb8a0183c4d7`;
-> historical convergence is evidence only. ADR 0288 remains Proposed while Draft,
-> and package/frontend/runtime release identity must converge at 2.45.0 before promotion.
+Fresh protected references:
-> Exact-head loop overlay: 2026-08-30 22:18 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` after unauthorized squash
-> of leftover-map coordinates (v2.24.0 / #782). Revert #808
-> (`revert-pr782-unauthorized` @ `1af3e53e`) restores `main` toward
-> `fc13acaa` (v2.23.0) and still needs independent APPROVE. GitHub
-> writes work (comment/close/create-PR/push). Token still has empty
-> `X-OAuth-Scopes`; repo permission is ADMIN. Open leftover stack
-> still lacks independent APPROVE. Do not self-approve.
-> #782 leftover-map coordinates through pair-segment distance
-> (v2.24.0–v2.28.0 / ADR 0267–0271) is `9bdd3e4d`. #802 explained
-> leftover share on pair segments (v2.30.0 / ADR 0273, includes v2.29
-> reconstruction) is `79ec22f0`. #803 unexplained leftover share on pair
-> segments (v2.31.0 / ADR 0274) is `089a1571`. #804 leftover-map cross
-> share on pair segments (v2.32.0 / ADR 0275) is `c513002b`. #805 leftover-map
-> unexplained leftover `U` on pair segments (v2.33.0 / ADR 0276) is
-> `e3fdfd74`. #806 leftover residual `R` on pair segments (v2.34.0 /
-> ADR 0277) is `33f6c3dd`. #809 leftover observed `Y` on pair segments
-> (v2.35.0 / ADR 0278) is `b334b00e`. #810 leftover expected `E` on pair
-> segments (v2.36.0 / ADR 0279) is `6e37757a`. #811 leftover-map rank on
-> pair segments (v2.37.0 / ADR 0280) is `e626a1d0`. #812 leftover-map
-> complete-case coverage on the graphic (v2.38.0 / ADR 0281) is `64964cb6`.
-> #813 leftover-map item complete-case coverage on the graphic (v2.39.0 /
-> ADR 0282) is `de2a8a8b`. #814 leftover-map incomplete post coverage on
-> the graphic (v2.40.0 / ADR 0283) is `77292872`. #815 leftover-map
-> incomplete item coverage on the graphic (v2.41.0 / ADR 0284) is
-> `63092de`. #816 leftover-map item complete-case coverage on the pair
-> list (v2.42.0 / ADR 0285) is `1e3d13e`. #817 leftover-map incomplete
-> post coverage on the pair list (v2.43.0 / ADR 0286) is `ef30930`. Leave
-> #782/#802/#803/#804/#805/#806/#808/#809/#810/#811/#812/#813/#814/#815/#816/#817 open for
-> independent review. Do not squash-merge stacked leftover PRs onto an
-> unprotected leftover base. Do not merge #808 without independent APPROVE.
-> Strix on #782 failed closed at `Run Strix (quick)`; do not weaken
-> fail-closed on `Vulnerabilities [1-9]`. Org Strix `ModelBehaviorError`
-> classifier is already on ContextualWisdomLab/.github. Copilot review is
-> not independent APPROVE. Issues #79 and #87 stay open. #96 is already
-> closed. Only collaborator is `seonghobae`; no independent reviewer can
-> be requested from this token.
-> Next buyer increment on this cycle: leftover-map incomplete item
-> coverage on the pair list (ADR 0287 / v2.44.0) delivered locally on
-> `feat/leftover-map-list-incomplete-item-v2440`. Caption the pair-list
-> note with persisted leftover-map incomplete item coverage so a
-> `used N of M scored criteria` note is not read as every scored
-> criterion entering the map. UI-only; no new columns. Missing,
-> non-integer, or negative dropped count, or a dropped count that
-> contradicts usable item complete-case integers, omits that leftover-map
-> incomplete item note. Dropped `0` is shown when persisted. Do not invent
-> dropped criteria from scored minus used, plotted criterion marker count,
-> leftover-map distance, leftover-map rank, leftover-map post coverage,
-> leftover-map item coverage, leftover-map incomplete post coverage, or
-> the count of unused axes. Do not invent leftover scores. Stack onto
-> leftover branch `feat/leftover-map-list-incomplete-post-v2430` / #817;
-> leave the PR open for independent review. Do not squash-merge onto the
-> leftover base. Do not persist leftover-map inner product, cosine, or
-> length as separate columns. Grouping comparison strip (ADR 0149) does
-> not gain this caption.
+- LineageWeave `main@83eba56149eb802cd63642c507c324c9976ec78e`, protected, signature valid.
+- Canonical reusable-workflow owner `ContextualWisdomLab/.github@e6334e229581a918e2f22de18733b76fa65d7e71`, protected, signature valid.
-> Exact-head loop overlay: 2026-08-30 21:35 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` after unauthorized squash
-> of leftover-map coordinates (v2.24.0 / #782). Revert #808
-> (`revert-pr782-unauthorized` @ `1af3e53e`) restores `main` toward
-> `fc13acaa` (v2.23.0) and still needs independent APPROVE. GitHub
-> writes work (comment/close/create-PR/push). Token still has empty
-> `X-OAuth-Scopes`; repo permission is ADMIN. Open leftover stack
-> still lacks independent APPROVE. Do not self-approve.
-> #782 leftover-map coordinates through pair-segment distance
-> (v2.24.0–v2.28.0 / ADR 0267–0271) is `9bdd3e4d`. #802 explained
-> leftover share on pair segments (v2.30.0 / ADR 0273, includes v2.29
-> reconstruction) is `79ec22f0`. #803 unexplained leftover share on pair
-> segments (v2.31.0 / ADR 0274) is `089a1571`. #804 leftover-map cross
-> share on pair segments (v2.32.0 / ADR 0275) is `c513002b`. #805 leftover-map
-> unexplained leftover `U` on pair segments (v2.33.0 / ADR 0276) is
-> `e3fdfd74`. #806 leftover residual `R` on pair segments (v2.34.0 /
-> ADR 0277) is `33f6c3dd`. #809 leftover observed `Y` on pair segments
-> (v2.35.0 / ADR 0278) is `b334b00e`. #810 leftover expected `E` on pair
-> segments (v2.36.0 / ADR 0279) is `6e37757a`. #811 leftover-map rank on
-> pair segments (v2.37.0 / ADR 0280) is `e626a1d0`. #812 leftover-map
-> complete-case coverage on the graphic (v2.38.0 / ADR 0281) is `64964cb6`.
-> #813 leftover-map item complete-case coverage on the graphic (v2.39.0 /
-> ADR 0282) is `de2a8a8b`. #814 leftover-map incomplete post coverage on
-> the graphic (v2.40.0 / ADR 0283) is `77292872`. #815 leftover-map
-> incomplete item coverage on the graphic (v2.41.0 / ADR 0284) is
-> `63092de`. #816 leftover-map item complete-case coverage on the pair
-> list (v2.42.0 / ADR 0285) is `1e3d13e`. Leave
-> #782/#802/#803/#804/#805/#806/#808/#809/#810/#811/#812/#813/#814/#815/#816 open for
-> independent review. Do not squash-merge stacked leftover PRs onto an
-> unprotected leftover base. Do not merge #808 without independent APPROVE.
-> Strix on #782 failed closed at `Run Strix (quick)`; do not weaken
-> fail-closed on `Vulnerabilities [1-9]`. Org Strix `ModelBehaviorError`
-> classifier is already on ContextualWisdomLab/.github. Copilot review is
-> not independent APPROVE. Issues #79 and #87 stay open. #96 is already
-> closed. Only collaborator is `seonghobae`; no independent reviewer can
-> be requested from this token.
-> Next buyer increment on this cycle: leftover-map incomplete post
-> coverage on the pair list (ADR 0286 / v2.43.0) delivered locally on
-> `feat/leftover-map-list-incomplete-post-v2430`. Caption the pair-list
-> note with persisted leftover-map incomplete post coverage so a
-> `used N of M scored posts` note is not read as every scored post
-> entering the map. UI-only; no new columns. Missing, non-integer, or
-> negative dropped count, or a dropped count that contradicts usable
-> complete-case integers, omits that leftover-map incomplete post note.
-> Dropped `0` is shown when persisted. Do not invent dropped posts from
-> scored minus used, plotted marker count, leftover-map distance,
-> leftover-map rank, leftover-map post coverage, leftover-map item
-> coverage, or the count of unused axes. Do not invent leftover scores.
-> Stack onto leftover branch `feat/leftover-map-list-item-coverage-v2420`
-> / #816; leave the PR open for independent review. Do not squash-merge
-> onto the leftover base. Do not persist leftover-map inner product,
-> cosine, or length as separate columns. Grouping comparison strip
-> (ADR 0149) does not gain this caption.
+Re-read both before merge or release; neither is a frozen dependency.
-> Exact-head loop overlay: 2026-08-30 21:22 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` after unauthorized squash
-> of leftover-map coordinates (v2.24.0 / #782). Revert #808
-> (`revert-pr782-unauthorized` @ `1af3e53e`) restores `main` toward
-> `fc13acaa` (v2.23.0) and still needs independent APPROVE. GitHub
-> writes work (comment/close/create-PR/push). Token still has empty
-> `X-OAuth-Scopes`; repo permission is ADMIN. Open leftover stack
-> still lacks independent APPROVE. Do not self-approve.
-> #782 leftover-map coordinates through pair-segment distance
-> (v2.24.0–v2.28.0 / ADR 0267–0271) is `9bdd3e4d`. #802 explained
-> leftover share on pair segments (v2.30.0 / ADR 0273, includes v2.29
-> reconstruction) is `79ec22f0`. #803 unexplained leftover share on pair
-> segments (v2.31.0 / ADR 0274) is `089a1571`. #804 leftover-map cross
-> share on pair segments (v2.32.0 / ADR 0275) is `c513002b`. #805 leftover-map
-> unexplained leftover `U` on pair segments (v2.33.0 / ADR 0276) is
-> `e3fdfd74`. #806 leftover residual `R` on pair segments (v2.34.0 /
-> ADR 0277) is `33f6c3dd`. #809 leftover observed `Y` on pair segments
-> (v2.35.0 / ADR 0278) is `b334b00e`. #810 leftover expected `E` on pair
-> segments (v2.36.0 / ADR 0279) is `6e37757a`. #811 leftover-map rank on
-> pair segments (v2.37.0 / ADR 0280) is `e626a1d0`. #812 leftover-map
-> complete-case coverage on the graphic (v2.38.0 / ADR 0281) is `64964cb6`.
-> #813 leftover-map item complete-case coverage on the graphic (v2.39.0 /
-> ADR 0282) is `de2a8a8b`. #814 leftover-map incomplete post coverage on
-> the graphic (v2.40.0 / ADR 0283) is `77292872`. #815 leftover-map
-> incomplete item coverage on the graphic (v2.41.0 / ADR 0284) is
-> `63092de`. Leave
-> #782/#802/#803/#804/#805/#806/#808/#809/#810/#811/#812/#813/#814/#815 open for
-> independent review. Do not squash-merge stacked leftover PRs onto an
-> unprotected leftover base. Do not merge #808 without independent APPROVE.
-> Strix on #782 failed closed at `Run Strix (quick)`; do not weaken
-> fail-closed on `Vulnerabilities [1-9]`. Org Strix `ModelBehaviorError`
-> classifier is already on ContextualWisdomLab/.github. Copilot review is
-> not independent APPROVE. Issues #79 and #87 stay open. #96 is already
-> closed. Only collaborator is `seonghobae`; no independent reviewer can
-> be requested from this token.
-> Next buyer increment on this cycle: leftover-map item complete-case
-> coverage on the pair list (ADR 0285 / v2.42.0) delivered locally on
-> `feat/leftover-map-list-item-coverage-v2420`. Caption the pair-list
-> note with persisted leftover-map item complete-case coverage so a
-> `used N of M scored posts` note is not read as the scored-criterion
-> census. UI-only; no new columns. Missing, non-integer, negative-used,
-> non-positive-scored, or used-greater-than-scored item coverage omits
-> that leftover-map item coverage note. Coverage `0 of M` is shown when
-> persisted. Do not invent item coverage from plotted criterion marker
-> count, leftover-map distance, leftover-map rank, leftover-map post
-> coverage, or the count of unused axes. Do not invent leftover scores.
-> Stack onto leftover branch `feat/leftover-map-plot-incomplete-item-v2410`
-> / #815; leave the PR open for independent review. Do not squash-merge
-> onto the leftover base. Do not persist leftover-map inner product,
-> cosine, or length as separate columns. Grouping comparison strip
-> (ADR 0149) does not gain this caption.
+Readiness is not acceptance. #983 and #1115 retain `CHANGES_REQUESTED`; no predecessor approval or workflow result transfers to moved heads. #1121 `dbabff85c72801a1a72a33dc69f969e032dc17b2` remains Ready but still requires current hosted GREEN and qualifying independent review.
-> Exact-head loop overlay: 2026-08-30 20:35 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` after unauthorized squash
-> of leftover-map coordinates (v2.24.0 / #782). Revert #808
-> (`revert-pr782-unauthorized` @ `1af3e53e`) restores `main` toward
-> `fc13acaa` (v2.23.0) and still needs independent APPROVE. GitHub
-> writes work (comment/close/create-PR/push). Token still has empty
-> `X-OAuth-Scopes`; repo permission is ADMIN. Open leftover stack
-> still lacks independent APPROVE. Do not self-approve.
-> #782 leftover-map coordinates through pair-segment distance
-> (v2.24.0–v2.28.0 / ADR 0267–0271) is `9bdd3e4d`. #802 explained
-> leftover share on pair segments (v2.30.0 / ADR 0273, includes v2.29
-> reconstruction) is `79ec22f0`. #803 unexplained leftover share on pair
-> segments (v2.31.0 / ADR 0274) is `089a1571`. #804 leftover-map cross
-> share on pair segments (v2.32.0 / ADR 0275) is `c513002b`. #805 leftover-map
-> unexplained leftover `U` on pair segments (v2.33.0 / ADR 0276) is
-> `e3fdfd74`. #806 leftover residual `R` on pair segments (v2.34.0 /
-> ADR 0277) is `33f6c3dd`. #809 leftover observed `Y` on pair segments
-> (v2.35.0 / ADR 0278) is `b334b00e`. #810 leftover expected `E` on pair
-> segments (v2.36.0 / ADR 0279) is `6e37757a`. #811 leftover-map rank on
-> pair segments (v2.37.0 / ADR 0280) is `e626a1d0`. #812 leftover-map
-> complete-case coverage on the graphic (v2.38.0 / ADR 0281) is `64964cb6`.
-> #813 leftover-map item complete-case coverage on the graphic (v2.39.0 /
-> ADR 0282) is `de2a8a8b`. #814 leftover-map incomplete post coverage on
-> the graphic (v2.40.0 / ADR 0283) is `77292872`. Leave
-> #782/#802/#803/#804/#805/#806/#808/#809/#810/#811/#812/#813/#814 open for
-> independent review. Do not squash-merge stacked leftover PRs onto an
-> unprotected leftover base. Do not merge #808 without independent APPROVE.
-> Strix on #782 failed closed at `Run Strix (quick)`; do not weaken
-> fail-closed on `Vulnerabilities [1-9]`. Org Strix `ModelBehaviorError`
-> classifier is already on ContextualWisdomLab/.github. Copilot review is
-> not independent APPROVE. Issues #79 and #87 stay open. #96 is already
-> closed. Only collaborator is `seonghobae`; no independent reviewer can
-> be requested from this token.
-> Next buyer increment on this cycle: leftover-map incomplete item
-> coverage on the graphic display (ADR 0284 / v2.41.0) delivered locally on
-> `feat/leftover-map-plot-incomplete-item-v2410`. Caption the leftover-map
-> graphic with persisted leftover-map incomplete item coverage so a
-> `used N of M scored criteria` caption is not read as every scored
-> criterion entering the map. UI-only; no new columns. Missing,
-> non-integer, or negative dropped count, or a dropped count that
-> contradicts usable item complete-case integers, omits that leftover-map
-> incomplete item caption. Dropped `0` is shown when persisted. Do not
-> invent dropped criteria from scored minus used, plotted criterion
-> marker count, leftover-map distance, leftover-map rank, leftover-map
-> post coverage, leftover-map item coverage, leftover-map incomplete
-> post coverage, or the count of unused axes. Do not invent leftover
-> scores. Stack onto leftover branch `feat/leftover-map-plot-incomplete-v2400`
-> / #814; leave the PR open for independent review. Do not squash-merge
-> onto the leftover base. Do not persist leftover-map inner product,
-> cosine, or length as separate columns. Pair-list note stays post
-> coverage (ADR 0168). Grouping comparison strip (ADR 0149) does not
-> gain this caption.
+## Customer Master / translation
-> Exact-head loop overlay: 2026-08-30 20:20 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` after unauthorized squash
-> of leftover-map coordinates (v2.24.0 / #782). Revert #808
-> (`revert-pr782-unauthorized` @ `1af3e53e`) restores `main` toward
-> `fc13acaa` (v2.23.0) and still needs independent APPROVE. GitHub
-> writes work (comment/close/create-PR/push). Token still has empty
-> `X-OAuth-Scopes`; repo permission is ADMIN. Open leftover stack
-> still lacks independent APPROVE. Do not self-approve.
-> #782 leftover-map coordinates through pair-segment distance
-> (v2.24.0–v2.28.0 / ADR 0267–0271) is `9bdd3e4d`. #802 explained
-> leftover share on pair segments (v2.30.0 / ADR 0273, includes v2.29
-> reconstruction) is `79ec22f0`. #803 unexplained leftover share on pair
-> segments (v2.31.0 / ADR 0274) is `089a1571`. #804 leftover-map cross
-> share on pair segments (v2.32.0 / ADR 0275) is `c513002b`. #805 leftover-map
-> unexplained leftover `U` on pair segments (v2.33.0 / ADR 0276) is
-> `e3fdfd74`. #806 leftover residual `R` on pair segments (v2.34.0 /
-> ADR 0277) is `33f6c3dd`. #809 leftover observed `Y` on pair segments
-> (v2.35.0 / ADR 0278) is `b334b00e`. #810 leftover expected `E` on pair
-> segments (v2.36.0 / ADR 0279) is `6e37757a`. #811 leftover-map rank on
-> pair segments (v2.37.0 / ADR 0280) is `e626a1d0`. #812 leftover-map
-> complete-case coverage on the graphic (v2.38.0 / ADR 0281) is `64964cb6`.
-> #813 leftover-map item complete-case coverage on the graphic (v2.39.0 /
-> ADR 0282) is `de2a8a8b`. Leave
-> #782/#802/#803/#804/#805/#806/#808/#809/#810/#811/#812/#813 open for
-> independent review. Do not squash-merge stacked leftover PRs onto an
-> unprotected leftover base. Do not merge #808 without independent APPROVE.
-> Strix on #782 failed closed at `Run Strix (quick)`; do not weaken
-> fail-closed on `Vulnerabilities [1-9]`. Org Strix `ModelBehaviorError`
-> classifier is already on ContextualWisdomLab/.github. Copilot review is
-> not independent APPROVE. Issues #79 and #87 stay open. #96 is already
-> closed. Only collaborator is `seonghobae`; no independent reviewer can
-> be requested from this token.
-> Next buyer increment on this cycle: leftover-map incomplete post
-> coverage on the graphic display (ADR 0283 / v2.40.0) delivered locally on
-> `feat/leftover-map-plot-incomplete-v2400`. Caption the leftover-map
-> graphic with persisted leftover-map incomplete post coverage so a
-> `used N of M scored posts` caption is not read as every scored post
-> entering the map. UI-only; no new columns. Missing, non-integer, or
-> negative dropped count, or a dropped count that contradicts usable
-> complete-case integers, omits that leftover-map incomplete post caption.
-> Dropped `0` is shown when persisted. Do not invent dropped posts from
-> scored minus used, plotted marker count, leftover-map distance,
-> leftover-map rank, leftover-map post coverage, leftover-map item
-> coverage, or the count of unused axes. Do not invent leftover scores.
-> Stack onto leftover branch `feat/leftover-map-plot-item-coverage-v2390`
-> / #813; leave the PR open for independent review. Do not squash-merge
-> onto the leftover base. Do not persist leftover-map inner product,
-> cosine, or length as separate columns. Incomplete item coverage on the
-> graphic remains unnamed.
+#929 `d4f42f579663e88a0c9af0cc492aa6ff7cae96ee` remains the PostgreSQL translation-ledger prerequisite for #932. The 37-key × 8-locale (`ko/en/ja/zh/vi/es/de/fr`) resource still needs independent language/product review, immutable one-way publication, authenticated browser consumption, permission/error/empty/loading states, CJK/text-expansion/font fallback, and current performance evidence. #996 remains gated by translation/read-model and Customer Master authorization prerequisites.
-> Exact-head loop overlay: 2026-08-30 19:48 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` after unauthorized squash
-> of leftover-map coordinates (v2.24.0 / #782). Revert #808
-> (`revert-pr782-unauthorized` @ `1af3e53e`) restores `main` toward
-> `fc13acaa` (v2.23.0) and still needs independent APPROVE. GitHub
-> writes work (comment/close/create-PR/push). Token still has empty
-> `X-OAuth-Scopes`; repo permission is ADMIN. Open leftover stack
-> still lacks independent APPROVE. Do not self-approve.
-> #782 leftover-map coordinates through pair-segment distance
-> (v2.24.0–v2.28.0 / ADR 0267–0271) is `9bdd3e4d`. #802 explained
-> leftover share on pair segments (v2.30.0 / ADR 0273, includes v2.29
-> reconstruction) is `79ec22f0`. #803 unexplained leftover share on pair
-> segments (v2.31.0 / ADR 0274) is `089a1571`. #804 leftover-map cross
-> share on pair segments (v2.32.0 / ADR 0275) is `c513002b`. #805 leftover-map
-> unexplained leftover `U` on pair segments (v2.33.0 / ADR 0276) is
-> `e3fdfd74`. #806 leftover residual `R` on pair segments (v2.34.0 /
-> ADR 0277) is `33f6c3dd`. #809 leftover observed `Y` on pair segments
-> (v2.35.0 / ADR 0278) is `b334b00e`. #810 leftover expected `E` on pair
-> segments (v2.36.0 / ADR 0279) is `6e37757a`. #811 leftover-map rank on
-> pair segments (v2.37.0 / ADR 0280) is `e626a1d0`. #812 leftover-map
-> complete-case coverage on the graphic (v2.38.0 / ADR 0281) is `64964cb6`.
-> Leave
-> #782/#802/#803/#804/#805/#806/#808/#809/#810/#811/#812 open for independent
-> review. Do not squash-merge stacked leftover PRs onto an unprotected leftover
-> base. Do not merge #808 without independent APPROVE. Strix on #782
-> failed closed at `Run Strix (quick)`; do not weaken fail-closed on
-> `Vulnerabilities [1-9]`. Org Strix `ModelBehaviorError` classifier is
-> already on ContextualWisdomLab/.github. Copilot review is not
-> independent APPROVE. Issues #79 and #87 stay open. #96 is already
-> closed. Only collaborator is `seonghobae`; no independent reviewer can
-> be requested from this token.
-> Next buyer increment on this cycle: leftover-map item complete-case
-> coverage on the graphic display (ADR 0282 / v2.39.0) delivered locally on
-> `feat/leftover-map-plot-item-coverage-v2390`. Caption the leftover-map
-> graphic with persisted leftover-map item complete-case coverage so two
-> criterion diamonds are not read as the scored-criterion census. UI-only;
-> no new columns. Missing, non-integer, negative-used, non-positive-scored,
-> or used-greater-than-scored item coverage omits that leftover-map item
-> coverage caption. Coverage `0 of M` is shown when persisted. Do not
-> invent item coverage from plotted criterion marker count, leftover-map
-> distance, leftover-map rank, leftover-map post coverage, or the count of
-> unused axes. Do not invent leftover scores. Stack onto leftover branch
-> `feat/leftover-map-plot-coverage-v2380` / #812; leave the PR open for
-> independent review. Do not squash-merge onto the leftover base. Do not
-> persist leftover-map inner product, cosine, or length as separate
-> columns.
+## Material UI / accessibility
-> Exact-head convergence note: the v2.37 leftover-map successor composition keeps the #802 explained-share foundation while retaining persisted unexplained-share, cross-share, unexplained-U, residual-R, observed-Y, expected-E, and rank captions plus the Vietnamese explained-share terminology regression. This branch remains review-gated; no predecessor check or approval is inherited.
+#977 is the single source owner for the leftover-pair actionable-name/browser lane. Fresh comparison previously exposed an invalid dual-writer state: #1041 and #977 had diverged from protected `main` while both modifying `LeftoverPairList`. The valid #1041 finding was adopted into #977 rather than continuing parallel source ownership; #1041 is merged documentation history and carries no continuing product-source authority.
-> Exact-head rendered-UX overlay: 2026-08-31 12:16 KST. PR #802
-> implementation revision `1e972d7f6` retains persisted-only `d`, `R̂`, and
-> `e` projection while moving dense segment captions off their plot segments
-> and painting them with the existing background token. The focused 32-test
-> plot selection, frontend lint, production build, and Storybook build pass.
-> Fresh synthetic `Reports/LeftoverMapPlot/ClosestAndFarthest` renders were
-> inspected at 1440-by-1000 and 390-by-844: the three captions are separated
-> from each segment and remain legible over axes; the fixed-width plot remains
-> intentionally horizontally scrollable at mobile width. Screenshots remain
-> temporary audit evidence and are not committed. This later documentation
-> overlay does not inherit those results; exact-head GitHub Checks and an
-> independent approval remain required before protected merge.
-> Exact-head release-contract overlay: 2026-08-31 11:46 KST.
-> Protected `main` remains `cb187cadee5fb6c46d8a944815ccc154a1e028d1`;
-> sixty-nine open PRs and ten open issues were enumerated in a fresh snapshot.
-> PR #780 remains on normal squash auto-merge with its exact-head product and
-> frontend checks successful, resolved review threads, and no independent
-> approval; its central required-workflow failures remain external protected
-> delivery blockers, so no merge SHA or protected-main Voice acceptance is
-> claimed. The next direct-to-`main` candidate, PR #802, exposed a release
-> identity conflict: Python package metadata and the frontend named v2.30.0
-> while `lineageweave.__version__` still named v2.20.0. Because that runtime
-> value is persisted as Event Lineage reconstruction provenance, the mismatch
-> was not documentation-only. Implementation revision
-> `88270da43cdb4a75349d10ab612b99690df59f45` synchronizes the runtime identity
-> and adds a repository contract test that binds Python metadata, runtime
-> provenance, and frontend release identity. Fourteen focused persistence,
-> channel-evidence, and release-contract tests pass. This later evidence-only
-> overlay does not transfer those results to its own head; current-head hosted
-> Checks and independent approval remain pending, and normal squash auto-merge
-> is retained. No mathematical value is recomputed in LineageWeave: the
-> leftover-map UI continues to render only persisted owner-produced values and
-> leaves missing or non-finite evidence unavailable. No self-approval, bypass,
-> force push, arbitrary weighting, or hidden-evidence substitution is used.
-> Exact-head loop overlay: 2026-08-31 06:31 KST. Protected `main` is
-> `cb187cadee5fb6c46d8a944815ccc154a1e028d1` (leftover-map coordinates,
-> graphic, axis share, ticks, and segment distance through v2.28.0, #782).
-> The live inventory contains 55 open PRs and 10 open issues. Parent #782 is
-> protected-merged; its first child #802 was therefore retargeted from the
-> merged feature branch to `main`, and its squash-history conflict is repaired
-> without force-push while preserving ADR 0272/0273 and v2.29.0/v2.30.0.
-> #771, #772, #774, and #780 remain exact-head blocked: normal squash
-> auto-merge is armed, no independent APPROVE exists, and failed hosted gates
-> remain fail-closed rather than being treated as product failures. #780's
-> focused Voice authority tests, frontend suite, lint, and build pass locally;
-> its desktop and mobile evidence distinguish the carrying Post action from
-> the separately authorized derivation-evidence action. This is candidate
-> evidence only: authenticated PostgreSQL API and rendered runtime proof are
-> still required before marking the Voice acceptance boundary complete.
-> Highest buyer-visible active gap in this slice: finish the protected parent-
-> first delivery of persisted leftover-map reconstruction `R̂` and explained
-> share `e` on graphic pair segments (#802), without recomputing either value in
-> LineageWeave. The implementation consumes the already persisted owner result,
-> omits missing/non-finite values, and has focused regression coverage. Parallel
-> stacked branches currently reuse release numbers (v2.46.0, v2.47.0, v2.50.0,
-> and v2.61.0); those branches are not release-ready and must be serialized and
-> renumbered after their common parent merges. No stacked child may be retargeted
-> or inherit Checks before its own parent is protected-merged.
+On #977, RED `2a9696b25ce2423ebfff48217ea2e0a31ee3630f` proves that a rich measurement-bearing `nextAction` could announce rank/Y/E or higher-priority evidence and then append the same formatter evidence again. Fix `57c60f622b0cbda0a746a99d3af9dd98b50c679b` records typed evidence ownership for the chosen action branch and removes only duplicate trailing accessible evidence. RED `5dd4a63bb007c27c23b26e5c3895f8fa9e6abe52` restores the separate accepted ADR 0162 visual invariant: a non-finite residual is visibly `R —` while remaining absent from the accessible name. Distance remains omitted when non-finite rather than fabricating `d NaN`.
-> Exact-head loop overlay: 2026-08-29 20:00 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. #782 leftover-map coordinates + graphic + axis share + ticks
-> + distance (v2.24.0–v2.28.0 / ADR 0267–0271) is on
-> `9bdd3e4d6e47a34ac22fca228b8d2a23d8cecca9` with auto-merge SQUASH
-> armed. Independent APPROVE is still required for protected main.
-> #801 leftover-map reconstruction on pair segments (v2.29.0 / ADR 0272)
-> squash-merged onto `feat/leftover-map-segment-distance-v2280` (not
-> onto #782); v2.29 is replayed onto the leftover-coordinates branch as
-> cherry-pick `5f21538e`. Do not squash-merge stacked leftover PRs onto
-> an unprotected leftover base. Auto-merge squash remains armed on
-> #782/#780/#774/#772/#771/#770. Drafts remain dirty against `main`.
-> #96 stays closed as a weaker duplicate of #91 (`state_reason` still
-> 403). GitHub writes through `gh`/MCP succeed (comment/create-PR/
-> auto-merge). Copilot review is not independent APPROVE. Do not
-> self-approve.
-> Next buyer increment on this cycle: leftover-map explained leftover
-> share `e` on graphic-display pair segments (ADR 0273 / v2.30.0)
-> delivered locally on
-> `feat/leftover-map-segment-explained-share-v2300`. Caption each
-> closest/farthest segment with persisted leftover-map explained leftover
-> share so the pair-row `R̂²/R²` badge matches the graphic. UI-only; no
-> new columns. Missing/non-finite `e` omits that explained leftover
-> share caption. A share greater than 1 is shown, never clamped. Do not
-> invent `e` from `R̂` and `R` or from plotted coordinates. Do not
-> invent leftover scores. Stack onto leftover branch
-> `feat/leftover-map-coordinates-v2240`; leave the PR open for
-> independent review. The following buyer increment is leftover-map
-> unexplained leftover share `s` on pair segments so `e + s + x = 1`
-> is graphic-auditable.
+Fresh review then found the rank-only zero edge case: `formatLeftoverMapRank(0)` admits and visibly renders persisted `rank 0`, while `LEFTOVER_RANK_ZERO_ACTION` explains the zero-rank state without literally naming that measurement. RED `7b6ff5bc16beb9c2ae91961bc753fb10ff3d7a89` pins the rendered/accessibility mismatch. Source fix `bce09c145b979e348d3db3ecad01246ff2d20ed9` preserves the existing localized zero-rank guidance and leaves the formatter badge unsuppressed only in that branch, so `rank 0` is announced exactly once. Rank-zero + observed/expected and non-zero rank paths retain their existing deduplication because their rich actions already name the numeric rank. No translation key or psychometric value changed.
-> Exact-head loop overlay: 2026-08-29 16:20 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. #782 leftover-map coordinates + graphic + axis share + ticks
-> (v2.24.0–v2.27.0 / ADR 0267–0270) is on
-> `2a203bf8b75b987ba899a0006a312d81259b9124`. #800 leftover-map distance
-> on pair segments (v2.28.0 / ADR 0271) is stacked on that leftover
-> branch at `1374a830582c22808c7ec02d4ae4cf2f5da55985`. Auto-merge squash
-> remains armed on #782/#780/#774/#772/#771/#770. Independent APPROVE is
-> still required for protected main. Drafts remain dirty against `main`.
-> #96 stays closed as a weaker duplicate of #91. GitHub writes through
-> `gh`/MCP succeed (comment/create-branch/auto-merge). Copilot review is
-> not independent APPROVE. Do not self-approve. Do not `gh pr merge`
-> stacked leftover PRs onto an unprotected leftover base.
-> Next buyer increment on this cycle: leftover-map reconstruction `R̂`
-> on graphic-display pair segments (ADR 0272 / v2.29.0). Caption each
-> closest/farthest segment with persisted leftover-map reconstruction
-> so the pair-row `R̂` badge matches the graphic. UI-only; no new
-> columns. Missing/non-finite `R̂` omits that reconstruction caption.
-> Do not invent `R̂` from plotted coordinates. Do not invent leftover
-> scores. Stack onto leftover branch
-> `feat/leftover-map-segment-distance-v2280`; leave the PR open for
-> independent review.
+The #977 lane retains component-scoped narrow-screen wrapping, 44px touch target, keyboard/focus, mouse/touch and Storybook Chromium acceptance harness. The latest source-bearing head had no pull-request workflow receipt at review time; Devin Review and CodeRabbit status success are not focused/frontend/full-suite/Storybook/Security/SAST/CodeQL acceptance or independent approval. Responsive leftover-map plot right-side clipping, text-expansion/CJK bounds, exact-head browser execution, security gates, and qualifying independent review remain open.
-> Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. #782 leftover-map coordinates + graphic + axis share + ticks
-> (v2.24.0–v2.27.0 / ADR 0267–0270) is on
-> `2a203bf8b75b987ba899a0006a312d81259b9124` after #799 squash-merged
-> into the unprotected leftover branch. Auto-merge squash remains armed
-> on #782/#780/#774/#772/#771/#770. Independent APPROVE is still
-> required for protected main. Drafts remain dirty against `main`. #96
-> stays closed as a weaker duplicate of #91. GitHub writes through
-> `gh`/MCP succeed. Copilot review is not independent APPROVE. Do not
-> self-approve. Do not `gh pr merge` stacked leftover PRs onto an
-> unprotected leftover base.
-> Next buyer increment on this cycle: leftover-map distance on
-> graphic-display pair segments (ADR 0271 / v2.28.0). Caption each
-> closest/farthest segment with persisted leftover-map distance `d` so
-> the pair-row badge matches the graphic line. UI-only; no new columns.
-> Missing/non-finite `d` omits that segment caption. Do not invent `d`
-> from plotted coordinates. Do not invent leftover scores. Stack onto
-> leftover branch `feat/leftover-map-coordinates-v2240`; leave the PR
-> open for independent review.
+#861 is the earliest App comparison owner. Parent #860 exact `13b838a3ea4d23b3d358d2f0adecec9c21cb0a8f` repairs exact numeric coordinate-tick identity: coordinates such as `0.501` and `0.504` remain distinct even when both display `+0.50`, and React keys use the persisted numeric value. Current #861 exact `69bdb2fc7613aeffd972cf2a114da1a9347fe505` then preserves that repair while replacing inherited share-only App expectations with exact persisted σ+share names and right-bounding both SVG axis captions. Commit `d572f651...` also retains desktop/mobile Storybook screenshot evidence. These are source/local-render repairs, not protected delivery.
-> Exact-head loop overlay: 2026-08-29 13:15 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. #782 leftover-map coordinates + graphic display + axis share
-> (v2.24.0 / v2.25.0 / v2.26.0 / ADR 0267 / ADR 0268 / ADR 0269) is on
-> `4a0afbf4804d9862bba58869db20ccdfb0a0b37e`; Strix fail-closed and no
-> independent APPROVE. Auto-merge squash remains armed on
-> #782/#780/#774/#772/#771/#770. Drafts remain dirty against `main`.
-> #96 stays closed as a weaker duplicate of #91. GitHub writes through
-> `gh`/MCP succeed (comment/create-branch/auto-merge). `git push` HTTPS
-> still fails (empty `X-OAuth-Scopes`). Copilot review is not
-> independent APPROVE. Do not self-approve.
-> Next buyer increment on this cycle: leftover-map coordinate ticks
-> (ADR 0270 / v2.27.0). Tick leftover-map axes at the origin and at each
-> unique finite persisted `ξ` / `ζ` so pair-row `ξ (x, y) ζ (x, y)`
-> matches the graphic. UI-only; no new columns. Rank-0 unused axes name
-> only `0` and do not invent drawing-scale `−1` / `+1` ticks. Do not
-> invent leftover scores. Do not mix into #782; stack onto leftover
-> branch `feat/leftover-map-coordinates-v2240`.
+The original axis-2 σ/share clipping finding is therefore source-repaired rather than pending source work. Dense origin-adjacent tick collisions, the fixed-width plot's mobile horizontal-scroll behavior, text-expansion/CJK bounds, and authenticated browser acceptance remain separate buyer-visible evidence gaps. Exact-head Tests `35536928685` is queued, and the clipping review thread remains open until current-head rendered/bounding acceptance and hosted checks are GREEN.
-> Exact-head loop overlay: 2026-08-28 19:15 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. #782 leftover-map coordinates + graphic display (v2.24.0 /
-> v2.25.0 / ADR 0267 / ADR 0268) is on
-> `2f7e9c8df695f12d03964d5caa68fa3355bdd923`; Strix fail-closed and no
-> independent APPROVE. Drafts remain dirty against `main`. #96 stays
-> closed as a weaker duplicate of #91. GitHub writes through MCP succeed
-> (comment/create-branch/git push/auto-merge). Copilot review is not
-> independent APPROVE. Do not self-approve.
-> Next buyer increment on this cycle: leftover-map axis share on the
-> graphic display (ADR 0269 / v2.26.0). Caption plot axes with persisted
-> ADR 0148 `leftover_map_axes` inertia `σ_k² / Σ_j σ_j²`. UI-only; no
-> new columns. Rank-0 zero-share axes still named. Missing/non-finite
-> share omits that axis badge and keeps existing leftover-map axis
-> text. Do not invent leftover scores. Do not mix into dashboard stacks
-> #640/#778/#781.
+## Report / comparison stack
-> Exact-head loop overlay: 2026-08-28 16:05 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. #782 leftover-map coordinates (v2.24.0 / ADR 0267) is on
-> `e2d13019004a5d8c019fecf7a39ceeef4093b8dd`; Strix fail-closed and no
-> independent APPROVE. Drafts remain dirty against `main`. #96 stays
-> closed as a weaker duplicate of #91. GitHub writes through MCP succeed.
-> Next buyer increment on this cycle: leftover-map graphic display
-> of already-persisted `ξ_{1:2}` / `ζ_{1:2}` (ADR 0268 / v2.25.0).
-> UI-only; no new columns. `R̂` and `d` already are inner product and
-> length. Do not invent leftover scores. Do not mix into dashboard
-> stacks #640/#778/#781.
+Active ancestry is code-current through the owner repair stack:
-> Exact-head loop overlay: 2026-08-28 13:00 KST. Protected `main` is
-> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map
-> explained leftover share, #775). Open ready PRs still lack independent
-> APPROVE. Drafts remain dirty against `main`. #96 stays closed as a
-> weaker duplicate of #91. GitHub writes through `gh` succeed.
-> Next buyer increment on this cycle: leftover-map coordinates
-> `ξ_{1:2}` / `ζ_{1:2}` (ADR 0267 / migration 0245 / v2.24.0) so
-> `R̂ = ξ · ζ` and `d = ‖ξ − ζ‖` are buyer-auditable. Do not name
-> leftover-map inner product, cosine, or length as separate columns.
+`#861 69bdb2fc... → #862 21ee0adc... → #863 7f1b97eb... → #865 688643cf...`
-> Exact-head loop overlay: 2026-08-28 10:00 KST. Protected `main` was
-> `edf22ee39aee2a8481f9bda8fff59801821e79c2` (#773 similar-VOC coverage).
-> Open ready PRs: #772 (ask_time_axis coverage), #771 (fixtures/vision
-> coverage), #770 (project-history empty-state). Auto-merge squash is
-> enabled on all three; none has an independent APPROVE (only bot
-> COMMENT). Drafts #702, #679, #672, #667, #640 remain dirty against
-> `main`. #96 stays closed as a weaker duplicate of #91. Writes through
-> the Grok GitHub App now succeed (comment/close/auto-merge/update-branch)
-> despite empty `X-OAuth-Scopes`; git push is the remaining probe this
-> cycle. This overlay supersedes every older queue count below.
-> Next buyer increment on this cycle: leftover-map explained leftover
-> share `e = R̂² / R²` (ADR 0266 / migration 0244 / v2.23.0) so
-> `e + s + x = 1` is buyer-auditable. Do not persist leftover-map
-> coordinates in this slice.
+#866 final source `8d63271c4644b39d11d65263cc59e8fca8a548cd` was normally merged into #865; its valid v2.82 product/test/ADR/CHANGELOG delta is materially present in #865 exact `688643cf317da7ad5b52bd0414dfae1e66da9bbb`. #867 exact `6b2611ce4d2d7d58acfcbe6b86a5fe640a41ef66` sits on that active parent and preserves only its comparison-axis badge delta.
-> Exact-head loop overlay: 2026-08-28 KST. Protected `main` was
-> `bbb191924e9881a5201f1ecf63c854d92992cc1c`; seven PRs and nine issues were
-> open. PR #763 was `b51d3bd8872b` and PR #762 was `e6ca33dba1b5`; both were
-> mergeable, normal squash auto-merge was enabled, exact-head Checks were still
-> running, and no qualifying independent approval existed. PRs #702
-> (`93e7b81d096d`), #679 (`135dfe7c4266`), #672 (`a3e87a89185f`), #667
-> (`0c0f4af572a9`), and #640 (`bd73e0a43ae1`) remained draft and dirty against
-> `main`. Central ruleset 18156473 and repository no-force-push ruleset
-> 21065108 remain active. This overlay supersedes every older queue count below.
-> Checks from older heads, stacked bases, or merged PRs are not transferred.
-> Current-runtime boundary: the official Compose project was healthy at the
-> HTTP health route, but its PostgreSQL schema did not yet contain
-> `source_post_voice`; therefore no current Voice-history aggregate,
-> authenticated project-history API result, or rendered authenticated UI result
-> is claimed. Older aggregate observations below remain dated supporting
-> evidence, not confirmation of this exact head. The checked repository names
-> are `ContextualWisdomLab/LineageWeave`, `RankWeave`, `ThreadWeave`, `TEPP`,
-> and lowercase canonical `ContextualWisdomLab/disksage`.
+Descendants continue on ordinary/non-force ancestry:
-> Voice-of-X delivery snapshot: 2026-08-27 KST. Protected `main` was
-> `ff7431bd1851c03e737808d22c6a2d43968582f9`; PR #713 was
-> `850494c3861703862a76cfe564381a41243c6c2d`; stacked PR #717 was
-> audited at implementation head
-> `d5fe4828e9005f0157c308e8ea3c3a590cdf465b`. This candidate and the
-> historical evidence below are not protected-main release evidence.
-> Loop snapshot: 2026-08-27. Protected `main` advanced through the
-> I/O-Psychology job-family and occupational-classification delivery: PRs
-> #709 (DOT/FJA worker functions, ADR 0232), #718 (evidence-bound construct
-> classes, ADR 0248), +#726 (catalog-bound construct extraction, ADR 0253),
-> #733 (construct evidence navigation, ADR 0255), #713 (Voice-of-X ADR 0246),
-> #753 (FJA I/O-Psychology semantic layer, ADR 0251), #751 (SOC/O*NET/RIASEC
-> taxonomy, ADR 0245), #749 (authorized job-family and job-series snapshot
-> import, ADR 0263), #657 (TEPP lifecycle evidence), #704, #720, and #754 are
-> now merged. The still-open queue is carried in section 1. No row below is
-> release evidence until re-verified on a specific head.
+`#867 6b2611ce... → #868 9ff3995b... → #869 e553f8ed... → #870 cc9f2d7b... → #871 014e7418... → #872 69119bb0... → #873 4949dd54... → #874 abb9d2c2... → #875 66eab13b...`
-## Voice-of-X product and technical gap
+#875 children are #876 `473d5f20d69584db3eaa7e129f7a8650ecd472bb` → #1033 `459b8af62763b6900cb0cb163fe3a64ea81fdaa5` → #1034 `0c1a97266f74b6963a765b7b78830146687861e9`, and sibling #877 `f294cc404a43ed011bba9b1291afad910838a669`. Historical #878/#879 remain delta carriers until verified GREEN succession proves every valid delta/test/fixture/contract/evidence artifact is inherited.
-ADR 0246 and PR #713 add Supplier, Employee, Business, Regulator, Investor,
-Society, and Process to the original Customer, Customer's Customer,
-Competitor, Market, and Partner source-post vocabulary. The migration,
-published SKOS concepts, product requirements, changelog, and ontology
-round-trip tests agree on the twelve codes. The design is organization-type
-neutral: public bodies, nonprofits, communities, and automated processes do
-not need to be forced into a B2B2C customer chain.
+#1034 was repaired after a first ordinary two-parent graft exposed a stale-tree regression. The intermediate head was not accepted. Final `0c1a9726...` fast-forwards from that head with a tree rebuilt from current #1033 plus exactly four valid post-coordinate/accessibility files. Current #1033 is the exact merge-base, `behind_by=0`; numeric tick identity and right-bounded axis captions remain inherited. #1034 Tests are skipped/cancelled/queued rather than GREEN, and one executable-accessibility review thread remains open pending exact-head GREEN.
-The phrase "all Voice-of-X combinations" does not have a standards-backed
-finite enumeration. ISO's own stakeholder-category guidance says that the
-relevant category set varies by committee and subject; ISO 26000 requires
-stakeholder identification and engagement across organizational contexts;
-AA1000SES requires an inclusive, continuing identification process; and
-Mitchell, Agle, and Wood (1997) model stakeholder salience from combinations
-of power, legitimacy, and urgency rather than a fixed industry-role list.
-Accordingly, ADR 0246 keeps the controlled vocabulary extensible and refuses
-keyword inference, defaults, invented weights, or an asserted exhaustive
-cross-product.
+The recovered predecessor #1033 frontend failure remains useful historical causal evidence: share-only `leftover map comparison axis 1 (82%)` contradicted rendered persisted `leftover map comparison axis 1 (σ 1.84, 82%)`. Current #861 source has repaired that mismatch; the predecessor failure is not acceptance for moved descendants.
-ADR 0256 and migration 0237 now define the persistence contract for
-evidence-bearing composition. A post keeps one source-provided
-`voc_type_code`, mirrored as its sole primary association, while every
-additional voice requires a normalized PROV-O assertion and explicit truth
-status. Half-open assignment intervals preserve a backfilled primary at
-historical cutoffs, close a replaced primary without deleting it, and permit a
-later return to the same Voice. The #717 candidate therefore addresses #748's
-A → B → A storage root cause without adding Cartesian-product codes. Protected
-delivery and synthetic PostgreSQL concurrency/cutoff evidence remain required.
-The remaining acceptance boundary is:
+The OpenTelemetry `LoggingHandler` deprecation remains separately owned by #973 `182d3c9d4c5f2a8ab2d63e77b8a9ced663a183f6`; report lanes must consume that repair through protected integration or verified succession.
-1. preserve the imported primary voice without reclassification (implemented
- in the candidate migration; migration 0237 replayed twice successfully on
- an isolated PostgreSQL stack on 2026-08-27, including both primary-sync
- triggers; a synthetic real-OIDC PostgreSQL API write also proved that the
- imported primary remains unchanged);
-2. record each additional voice with its own source/evidence and truth state
- (schema-enforced and candidate `post_admin` API plus live Post-popup
- authoring implemented; synthetic authenticated PostgreSQL integration
- proved denial before permission, the authorized write, and its normalized
- PROV-O derivation on 2026-08-27);
-3. keeps post voice distinct from named-counterparty relationship, actor role,
- topic, channel, lifecycle, and stakeholder-salience attributes;
-4. return only authorized associations through API, JSON-LD, CSV, filters,
- and UI (candidate API list/detail, filters, combined post-card labels,
- qualified JSON-LD, exact-value CSV, SHACL, and source-post evidence
- navigation implemented; the board re-filter matches every associated voice
- and all twelve governed atomic labels are localized across English, Korean,
- Chinese, Japanese, and Vietnamese; one bounded query projects assignments
- for every authorized Post even when another node type is the focus; post
- detail lists primary and evidence-connected perspectives separately and
- honors its knowledge cutoff; client-side JSON-LD filtering retains only
- exact canonical repository-case node and Voice-assignment IRIs rather than
- accepting cross-origin suffix matches; the exact-value row exposes distinct
- carrying-Post and authorized derivation-evidence actions, while hidden
- evidence emits neither an identifier nor a fabricated evidence count;
- paged JSON-LD merges properties for one subject and unions its multi-Voice
- relation rather than overwriting an earlier page); and
-5. proves zero-, one-, and multi-voice states with synthetic fixtures,
- migration replay, ontology/SHACL, API, accessibility, and Storybook edge
- tests before any release claim. The candidate `CombinedVoiceEvidence` scene
- covers primary-plus-additional assignments; desktop and mobile screenshots
- were inspected on 2026-08-27. At 390 CSS pixels the document did not
- overflow, the named exact-value region remained horizontally scrollable,
- and the source-post evidence action remained visible and labeled. The
- `Post/Recorded perspectives` desktop and 390-pixel scenes were also inspected
- on 2026-08-27; both kept each complete Voice label paired with its imported
- or evidence-connected state without clipping or horizontal overflow. The
- `Post/Connect perspective` ready/success scenes were inspected at 1440 and
- 390 CSS pixels on 2026-08-27: labels stay above controls, the mobile form is
- a single column, controls meet the 44-pixel touch target, and no horizontal
- overflow was visible.
+## Summary-read catalog authorization
-At this snapshot the repository had 42 open PRs and 11 open issues. PR #713
-head `850494c3` includes the review-driven localization of all twelve governed
-Voice labels. Its frontend, ontology publication, static-analysis, dependency,
-coverage, full-suite, CodeRabbit, Devin, and OpenCode checks passed. Strix
-failed closed before producing a vulnerability report:
-the primary NVIDIA NIM model returned HTTP 429, one configured fallback had
-reached end of life, and the OpenAI fallback reported exhausted credits. A
-same-head retry completed on 2026-08-27 with the explicit
-`STRIX_PROVIDER_UNAVAILABLE` annotation and again produced no vulnerability
-report. This
-is provider/control-plane unavailability, not a vulnerability result or
-permission to transfer an older success. Auto-merge remains enabled, while an
-independent approval is still required. PR #717 implementation head
-`d5fe4828` merges that
-parent change without force-pushing and separates the complete governed Voice
-catalog used for authoring from usage-derived Board filters, so an authorized
-administrator can attach a Voice that no visible Post carries yet. It also
-labels Voice exact-value navigation as opening the carrying Post rather than
-misrepresenting that Post as the separately recorded derivation evidence. Its
-CodeRabbit and hosted Frontend/Storybook checks passed at predecessor head
-`ebb4ef1d`; refreshed checks for exact head `d5fe4828` were queued. Focused local
-backend tests, frontend type checking/lint, and the new unused-Voice authoring
-regression passed, and the exact-value navigation tests, lint, and type check
-passed after the label repair. The paged JSON-LD union regression and Voice
-evidence navigation suite passed 23 focused frontend tests; 48 focused backend
-ontology/docstring tests also passed. The full backend suite at predecessor
-head `ebb4ef1d` passed 1,366 tests with 148 environment-dependent skips. The
-real-integration fixture now applies
-the existing migration 0042 before the expanded taxonomy migrations instead
-of seeding an incomplete or duplicate legacy catalog; the exact
-`d5fe4828` authenticated post-list integration passed in 91.54 seconds. The
-wider local frontend run had 400 passes and eight five-second timeouts under
-concurrent backend-suite load; a later App-only run had 94 passes and five
-five-second timeouts, while the hosted Frontend/Storybook job passed on
-`ebb4ef1d`. Neither local timeout run is promoted to full-suite success. An initial
-authenticated integration attempt was unavailable while Keycloak initialized;
-a later retry against the shared synthetic stack succeeded in 56.18 seconds
-and proved the permission, API, PostgreSQL,
-PROV-O, and primary-preservation assertions; no identifying source data was
-used or retained. No self-approval, admin bypass, or stale-head check transfer
-is permitted.
+#1078 remains a separate critical authorization/integrity owner from #1077/#1080. A `post_read`-authorized `GET /api/posts/{post_id}/summary` may derive and persist its summary projection, but it must not gain the capability to create or mutate the shared `corporate_entity` catalog or hierarchy. The causal repair must keep summary-read behavior intact while admitting live hierarchy-inference/relation-verification catalog mutation only for explicit `post_admin` authority; exact-match consumption of already-known catalog identities may remain read-only. #1077/#1080 continue to own connection-lease/TOCTOU lifetime rather than this permission boundary.
-Stacked PR #717 carries ADR 0256, migration 0237, qualified
-ontology terms, persistence/API/UI tests, and the category-validation review
-repairs plus a local candidate admin write path that creates its PROV-O
-derivation from an authorized evidence Post. Its JSON-LD projection names that
-evidence Post only when it is in the authorized visible set and omits the whole
-additional assignment otherwise, preserving the SHACL evidence minimum without
-substituting the assigned Post. It targets
-#713's branch, not protected `main`;
-its checks and review are candidate evidence only. After
-#713 reaches protected main, #717 must be synchronized, retargeted to `main`,
-and revalidated on its then-current head.
+#1078 remains RED until executable real-service evidence proves a `post_read` account leaves global catalog rows/content invariant, a `post_admin` account retains the intended enrichment path, provider/network mutation capability is absent from the low-privilege path, and exact-head security evidence clears the original finding.
-Downstream Dashboard repair PR #737 exact head `a837ee5d` is stacked on base
-`7c7bb2cf`, which contains migration 0235 through a non-#713 composition but
-does not contain #713's twelve-label locale update. Its added Voice labels are
-therefore necessary on that exact base, yet overlap #713 and must be reconciled
-when the stack is eventually rebuilt on protected `main`; neither branch is a
-second taxonomy authority, and pre-parent Checks cannot transfer across that
-restack.
-The remaining user-visible gap is evidence-bearing composition. A post still
-has one source-provided `voc_type_code`; the product cannot yet represent a
-single record that intentionally carries multiple independently evidenced
-voices, nor expose the combination in filters, exports, or the ontology
-neighborhood. Do not solve this by adding every Cartesian-product code. The
-acceptance boundary for a later ADR is a normalized, provenance-bearing
-multi-voice association that:
+## Authentication / authorization stack
-1. preserves the imported primary voice without reclassification;
-2. records each additional voice with its own source/evidence and truth state;
-3. keeps post voice distinct from named-counterparty relationship, actor role,
- topic, channel, lifecycle, and stakeholder-salience attributes;
-4. returns only authorized associations through API, JSON-LD, CSV, filters,
- and UI; and
-5. proves zero-, one-, and multi-voice states with synthetic fixtures,
- migration replay, ontology/SHACL, API, accessibility, and Storybook edge
- tests before any release claim.
+Current authority:
-At this snapshot the repository had 23 open PRs and 10 open issues. PR #713
-was `MERGEABLE` but policy-blocked: exact-head backend, frontend, CodeQL,
-ontology-publication, Semgrep, OSV, Trivy, Scorecard, Noema, Devin, and
-CodeRabbit checks were successful; `coverage-source-tree` was queued; Strix
-failed closed with `STRIX_PROVIDER_UNAVAILABLE`; and an independent approval
-was still required. Auto-merge remains enabled. No self-approval, admin bypass,
-or stale-head check transfer is permitted.
+`#899 c943060c7c16f74faf48d1ee40eaa5301c830065 → #1118 e661211f10df1afffa99ab1647a7d94074a5ad81 → #1120 5cc0dc509efb17ae5b1746b64660e26a604f67c7 → #1117 2769b92172dd089ae9ffec207c9130abe057a728`.
-References for this gap use the APA 7 entries in ADR 0246. Current supporting
-standards pages were rechecked on 2026-08-27: ISO 26000:2010 remains applicable
-to all organization types and AA1000SES v3 is under development for a planned
-2027 release, so the repository continues to cite the published AA1000SES
-(2015) contract rather than treating the draft as adopted policy.
+Accumulated #1120 verifier/auth-fixture prerequisites remain in force: contradictory RSA/JWK metadata is rejected; `x5c` must be canonical/parseable and consistent with JWK `n/e` and KeyUsage; unsupported `x5u` candidates fail closed because LineageWeave owns no remote-certificate retrieval/trust path; service-account subjects come from the checked-in realm fixture and remain disjoint from human subjects; machine clients are unique enabled OIDC confidential service-account clients with direct/browser/implicit grants disabled and required REST/MCP audiences. The public browser fixture remains Authorization Code + S256 PKCE with implicit flow disabled and exact local redirect origins.
-> Current queue overlay: 2026-08-27 KST. Protected `main` was
-> `ff7431bd1851c03e737808d22c6a2d43968582f9`; 26 PRs and 10 issues were
-> open. This overlay supersedes the older queue count and exact-head table
-> below, which remain historical evidence. Re-fetch the head, checks, reviews,
-> threads, applicable rulesets, and merge SHA immediately before any lifecycle
-> claim. No local branch or stacked-branch result is protected-main evidence.
+Seed/bootstrap ROPC is source-repaired. Human fixture subjects are read deterministically from `docker/keycloak/realm-export.json`; seed no longer logs into master `admin-cli` or mints a human password token. `scripts/warm_seeded_post_content.py`, `scripts/smoke_test_oidc.py`, and k6 HTTP/MCP paths use confidential Client Credentials actors rather than public-browser password grants.
-## Current occupational semantic-layer gap
+The final backend-integration ROPC finding remains source-repaired on current #1120 `5cc0dc509efb17ae5b1746b64660e26a604f67c7`: `backend/tests/test_api.py` uses distinct confidential viewer/admin helpers and `lineageweave-frontend.directAccessGrantsEnabled=false` remains in the same causal migration. #1120's move from the earlier repair head is parent convergence onto current #1118, not a rollback of that source contract. Exact-head Tests `35559128056` is Draft-policy skipped, so source repair is not hosted GREEN.
-ADR 0245's candidate branch publishes only a provenance-safe classification
-foundation: 23 2018 SOC major groups, four O*NET 31.0 Job Zone categories, six RIASEC interest
-types and their published adjacency, six explicitly legacy work-value clusters, seven
-revised work-style dimensions, and four ability domains. It asserts no
-occupation-to-characteristic instance profile and therefore does **not** yet
-satisfy the requested job-family, job-series, and occupation-level coverage of
-work cognition, affect, behavior, or their empirical relations. This is an
-explicit unavailable state, not a reason to infer mappings from labels.
+The machine helper retains four causal hardening steps: endpoint override; Compose empty/unset-secret parity; repository-known fallback-secret restriction to `localhost`/`127.0.0.1`/`::1`; and fail-closed rejection of explicit confidential-client secrets over non-loopback cleartext HTTP. Loopback HTTP remains a disposable local-fixture exception. ADR 0028 records the RFC 6749 TLS/client-credential boundary plus the existing RFC 9700 / RFC 10017 boundary.
-| Gap | Current evidence | Acceptance requirement |
-|---|---|---|
-| Classification depth | ADR 0245 and `lineageweave/io_taxonomy.py` expose SOC major groups only; schemes now name versioned PROV source entities and the stable O*NET 31.0 Job Zone JSON digest | Import a versioned authoritative classification release with provenance-preserving major, minor, broad, and detailed occupation identifiers; add ISCO/ESCO crosswalks only where the publishing authority supplies them |
-| Construct granularity | The candidate ontology exposes 23 high-level characteristic concepts | Publish source-versioned O*NET abilities, skills, knowledge, work activities, work context, interests, and work styles without collapsing cognition, affect, and behavior into one dimension; preserve removed Work Values only as versioned legacy content |
-| Occupation-to-construct relations | ADR 0245 deliberately declares relation properties without instance assertions | Persist released source observations with source version, occupation code, element identifier, scale identifier, value, sample/error metadata when supplied, and provenance; never invent or locally normalize a weight |
-| Job-family and job-series semantics | No authoritative employer-specific job architecture is present | Define an organization-neutral import contract that preserves the authorized source hierarchy and distinguishes standard occupation codes from employer job families/series; no label-based binding |
-| Temporal and multilevel interpretation | Static vocabulary only; no person-level inference is asserted | Version valid and transaction time, preserve occupation/organization/unit nesting and multiple membership, and require TEPP or the owning Rust psychometric service before any calibrated temporal or multilevel result |
-| Product consumption | The read model has no persisted semantic-layer consumer or authenticated UI evidence | Add a provenance-bearing API and accessible ontology exploration flow, then verify synthetic Storybook edge states plus authenticated aggregate runtime evidence without exposing identifying records |
+#1117 is ordinary/non-force converged on current #1120. Exact child `2769b92172dd089ae9ffec207c9130abe057a728` has #1120 `5cc0dc50...` as exact merge-base, `behind_by=0`, and effective delta only `README.md` plus the focused README auth-contract regression. That repair removes stale public-client ROPC/direct-grant claims while retaining current local-stack inventory.
-### Current exact-head PR queue
+#1118 separately owns the PyJWT declared-floor repair: both install surfaces require `pyjwt[crypto]>=2.13.0`, the committed lock resolves 2.13.0, owned JWT verification remains RS256-only, and `docs/doctoring/PYJWT_SECURITY_REFERENCES.md` records APA 7th traceability for CVE-2026-48523/48524/48525/48526. Current #1118 exact `e661211f...` is converged on #899 `c943060c...`; exact-head Tests `35558975815` remains Draft-skipped, so this is source-repaired rather than hosted GREEN.
-| PR | Exact observed head | Base | Observed gate state |
-|---:|---|---|---|
-| #719 | `0cea830a` | `feat/fja-worker-function-ontology` | unstable; 1 pending check(s) |
-| #718 | `a3fb32bb` | `feat/fja-worker-function-ontology` | clean; no non-passing check observed |
-| #717 | `771a8edf` | `feat/voice-of-x-complete-taxonomy` | unstable; 1 pending check(s) |
-| #716 | `8b54b2f7` | `fix/structured-workflow-exact-pin` | clean; no non-passing check observed |
-| #714 | `aa93318f` | `main` | blocked; no non-passing check observed |
-| #713 | `cc3dfc14` | `main` | blocked; review required; 13 pending check(s) |
-| #711 | `8902e37f` | `feat/dashboard-case-metrics` | clean; no non-passing check observed |
-| #710 | `8df04b68` | `main` | blocked; review required; no non-passing check observed |
-| #709 | `8ef4090c` | `main` | blocked; review required; 11 pending check(s) |
-| #704 | `027323cf` | `main` | blocked; review required; 2 failed check(s) |
-| #702 | `5de66ab9` | `main` | blocked; review required; 2 pending check(s) |
-| #701 | `cc3351a9` | `main` | blocked; review required; 1 failed check(s) |
-| #700 | `1bc99eca` | `main` | blocked; review required; 1 failed check(s) |
-| #680 | `efe864e5` | `main` | blocked; 1 failed check(s) |
-| #679 | `13ecf41d` | `main` | blocked; no non-passing check observed |
-| #672 | `a3e87a89` | `main` | blocked; review required; 1 failed check(s) |
-| #668 | `1194f44d` | `main` | blocked; review required; 1 failed check(s) |
-| #667 | `c2d11a8a` | `main` | blocked; review required; 2 pending check(s) |
-| #658 | `15d670f0` | `main` | blocked; review required; 1 failed check(s) |
-| #657 | `9f71681c` | `main` | blocked; review required; 1 failed check(s) |
-| #644 | `f53dd28e` | `main` | blocked; review required; 1 failed check(s) |
-| #643 | `8767de1b` | `main` | blocked; review required; 1 failed check(s); 1 pending check(s) |
-| #640 | `5594029c` | `main` | blocked; no non-passing check observed |
-| #639 | `2f4b1bff` | `main` | blocked; review required; 1 failed check(s) |
-| #632 | `24262a99` | `main` | blocked; review required; 1 failed check(s) |
-| #629 | `b721b0f2` | `main` | blocked; review required; 1 failed check(s) |
+#899 current exact `c943060c7c16f74faf48d1ee40eaa5301c830065` is Ready for validation admission only. Its repository/security/static-analysis workflows are queued and its Tests jobs remain runnerless; that state is not merge readiness. The four direct descendants have already been ordinary/non-force converged on this parent.
-> Dashboard delivery snapshot: 2026-08-26 07:15 KST. Protected `main` was
-> `494b54e2245040bcf02b45376f221c37cd437e76`. This local branch is not
-> protected-main release evidence.
+Remaining authentication work is acceptance/integration rather than ROPC source migration: obtain exact-head hosted GREEN where policy executes it; rendered Authorization Code + S256 PKCE redirect/callback/session/return-path/tampered-state/permission acceptance; authenticated PostgreSQL/buyer API evidence; and qualifying independent review before parent-first merge/retarget.
-## Operations Dashboard PRD/TRD traceability
+## Voice-of-X acceptance boundary
-| Requirement | Evidence contract | Delivery state |
-|---|---|---|
-| Claim cause delay: order, specification change, originating order, sales pool, Event/post counts | ADR 0206; contextual-orchestrator case classification with cited spans; Event Lineage context | Candidate implementation; authenticated runtime acceptance pending |
-| Rebid/handover: discussion, counterparties, our owner, decisions, Event/post counts | ADR 0206; normalized case facts plus persisted summary actions/roles | Candidate implementation; corpus backfill pending |
-| External information count/rate and sales/project relation | ADR 0206; semantic `external_information` classification inside Dashboard GNB | Candidate implementation; no separate Board by product decision |
-| Project-specific journey | Explicit source/semantic project membership plus event-time ordering | Candidate API and ordered journey UI implemented; authenticated runtime acceptance pending |
-| Repeat issue to design improvement | `repeat_issue`, `issue_pattern`, and `improvement_action` cited facts | Candidate semantic contract; design-system connector acceptance pending |
-| Natural-language Ask with evidence, report, alert, MCP | Persisted semantic-unit embeddings plus versioned delivery/resource contract | Candidate implementation uses whole-question embedding retrieval with no lexical fallback; authenticated runtime acceptance pending |
-| Similar VOC, customer cohort, prior action | Persisted repeat-issue candidate semantics plus orchestrator pair adjudication and extractive evidence | Candidate live post endpoint and post-detail UI implemented; authenticated runtime acceptance pending |
-| TEPP independent Event Lineage anchor | Accepted, persisted TEPP criterion bound to exact snapshot/cutoff before fast-mlsirm activation | Consumer PR #606 is on protected main; TEPP producer PR #237 remains open, so no end-to-end accepted artifact is release evidence yet |
-| Temporal Lineage topics and multilevel important posts | ADR 0210; TEPP posterior topic/plausible-value contract followed by fast-mlsirm observed-information case-deletion influence | Product/technical contract is protected on `main`; neither required Rust CPU/GPU producer envelope is shipped, so the Dashboard surface remains unavailable (ADR 0208: no local Python substitute) |
+Accepted ADR 0246 remains vocabulary authority: twelve atomic Voice codes, extensible scheme, no Cartesian-product combination codes. Implementation preserves one imported primary Voice and normalized additional assignments with explicit truth status and PROV-O derivation. API, exact-value CSV, and JSON-LD tests cover carrying-Post/evidence separation and paged multi-Voice union, but these source contracts do not prove live delivery.
-### Technical contract and flow
+Protected `main@83eba56149eb802cd63642c507c324c9976ec78e` has no newly collected exact-head authenticated PostgreSQL API receipt or desktop/mobile rendered acceptance for Voice history. A hidden evidence Post must omit the additional assignment rather than substitute the carrying Post, and cutoff reads must use the assignment interval effective at the cutoff.
-```mermaid
-sequenceDiagram
- participant Source as Authorized source_post
- participant CO as contextual-orchestrator
- participant Case as operations_case_* (3NF)
- participant TEPP as TEPP criterion run
- participant MLS as fast-mlsirm
- participant API as Dashboard/Ask API
- Source->>CO: semantic units + lineage + ontology context
- CO-->>Case: cases, cited facts, session provenance
- Source->>TEPP: versioned snapshot and independent criterion
- TEPP-->>MLS: exact accepted anchor only
- MLS-->>API: anchored vector or unavailable
- Case-->>API: ABAC-filtered evidence and counts
-```
+#1121 exact `dbabff85c72801a1a72a33dc69f969e032dc17b2` repairs ADR 0252 so Status/Context and the ADR index point to evidence-bearing ADR 0256 rather than unrelated ADR 0251. Local documentation hygiene is source-GREEN; hosted lanes remain non-accepting until completed successful exact-head checks. Canonical runner-owner issue `.github#712` owns first-runner acquisition / organization throughput where jobs remain runnerless; no LineageWeave wake commit substitutes for that owner repair.
-Security/operability: every aggregation applies `post_read` plus row-level
-corporate-entity visibility before counting; source-body digests invalidate
-stale inference; provider errors persist no positive/negative result; PII
-remains authorized at the UI boundary and is excluded from telemetry. The
-tables use composite keys and bounded kind-first indexes; production hot-path
-acceptance still requires `EXPLAIN (ANALYZE, BUFFERS)` on an anonymized runtime
-snapshot.
+## Performance / immutable delivery
-### Historical UI audit evidence
+#995 `dbe5ac54228162e3ad5a9c92460006fb5e49e935` remains performance RED because durable exact-head cold buyer-path evidence is absent. #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` remains MCP latency RED until representative profiling and causal hot-path work demonstrate p95 ≤20 ms without sample shrinking, hidden I/O, or unrealistic cache warm-up.
-The `f0b96029` Storybook build was rendered at 1440×1100 and 402×1200 with
-synthetic evidence; `416fd19d` changes only post-navigation request isolation.
-Desktop inspection showed all four case kinds, five non-conflated metrics,
-project-journey ordering, cited facts, and evidence actions without horizontal
-card overflow. Narrow inspection showed two-column metrics, readable cards and
-44px-class actions; the project journey remains intentionally horizontally
-scrollable. No identifying runtime record or screenshot is committed. The
-`EvidenceReady`, `NarrowViewport`, `AnalysisPendingAndMissingEvidence`,
-`AnalysisFailed`, and `LoadError` scenes cover the ADR 0206 state inventory.
-Authenticated authorized-corpus acceptance remains separate and may return
-only aggregate, non-identifying evidence to this repository.
+#961 `3bdec0504a65e63f44bd49ba15de37182a1672cc` repairs source version identity but is not a release. Publication requires one protected exact candidate with required gates, installed/built package identity, CHANGELOG, immutable tag/release/package, SBOM/provenance, reproducibility, and rollback evidence.
-### Exact open-PR boundary
+## Cross-PR identity and contract audit
-At this snapshot there were 11 open PRs and 10 open issues. PRs #660 and #659
-merged to protected `main`; PR #666 remains only non-default-branch stack
-composition inside #663. Every remaining open head required refreshed hosted
-gates and/or independent review after the base changed. These observations are
-not merge readiness. Re-fetch exact heads, unresolved threads, checks,
-approvals, rulesets, and merge SHA before any lifecycle claim.
+Open stacked work still has two release-identity collisions that must be resolved by parent-first protected integration rather than parallel publication: #843 and #844 both claim `v2.62.0`, while sibling #876 and #877 both claim `v2.92.0`. Their distinct API/UI deltas may remain separate review units, but one integrated release identity cannot name two divergent heads. Retarget descendants only after the selected parent merges, then refresh ADR, API, CHANGELOG, package, and exact-head evidence.
-> Audit snapshot: 2026-08-26 07:15 KST (refreshed by the autonomous merge
-> loop). This repository records synthetic fixtures and aggregate,
-> non-identifying runtime evidence only. Open PRs and local checks are not
-> protected-default-branch release evidence. Identifying post identifiers,
-> organization names, and production record keys must never appear in this
-> file.
+Migration ordinal uniqueness remains separately owned by #1049 `5322971193d1ff4e0ae13c054d8f99615934d4dc`; the baseline does not infer a schema repair before that exact head is reviewed and protected-integrated. PRD/ADR identity reconciliation remains open in #997 and Voice authority in #1121. No current evidence supports renumbering another PR's ADR or migration from this documentation branch.
-## 1. Exact-head and governance evidence
+## Buyer-gap register
-The protected default branch was `494b54e2245040bcf02b45376f221c37cd437e76`
-when this baseline was refreshed. The live queue contained 11 open PRs and 10
-open issues. The exact-head inventory below supersedes older per-PR snapshots
-elsewhere in this document; those older rows remain useful historical delivery
-context only.
+| Area | Current authority | State | Required causal next step |
+| --- | --- | --- | --- |
+| Translation / Customer Master | #929 → #932 → #996 | RED/Draft | PostgreSQL + canonical-owner checks, language review, browser/auth/performance acceptance |
+| Leftover-pair actionable accessibility | #977 live source owner; last source-bearing repair `bce09c14...`; #1041 merged history | source repaired / exact-head acceptance pending | exact-head frontend/full-suite + Storybook Chromium + security + locale/font-fallback + independent approval; no parallel source writer |
+| App comparison acceptance | #861 `69bdb2fc...` | source repaired / exact-head acceptance pending | completed successful current-head checks + authenticated browser/accessibility acceptance |
+| App comparison layout | #861 `69bdb2fc...` | source repaired / rendered acceptance pending | responsive + text-expansion/CJK browser bounds; keep dense tick/mobile-scroll risk explicit |
+| Report contracts | #862 → #863 → #865; merged #866; #867 → … → #875 → (#876 → #1033 → #1034, #877); historical #878/#879 | converged / fresh acceptance pending | exact-head repository/browser/a11y/security validation; predecessor failures stay diagnostic only |
+| Catalog connection leases / TOCTOU | #1077 / #1080 | separate owner lanes | prove short transactions around external work, then obtain protected integration evidence |
+| Summary-read shared corporate catalog mutation | #1078 | separate owner lane / RED | enforce the `post_read`/`post_admin` mutation boundary, preserve summary-read behavior, then obtain exact-head security evidence |
+| Telemetry deprecation | #973 | source repaired / integration pending | consume through protected integration or verified succession |
+| Canonical CI/CodeQL | `.github@e6334e22...` | live owner authority; queue owner #712 active | refresh consumers/receipts against current released owner contracts; keep runner starvation separate from product source |
+| Authentication | #899 `c943060c...` → #1118 `e661211f...` → #1120 `5cc0dc50...` → #1117 `2769b921...` | ROPC/helper/JWT source repaired; runtime/browser acceptance pending | exact-head hosted + PostgreSQL + rendered Authorization Code/S256 PKCE proof, then parent-first merge/retarget |
+| Voice ADR authority | #1121 `dbabff85...` | source repaired / hosted acceptance pending | exact-head GREEN + independent review + normal merge, then protected-main runtime evidence |
+| Frontend performance | #995 | RED | representative cold buyer-path measurement and causal repair if over budget |
+| MCP latency | #1009 | RED | representative profile and hot-path repair to p95 ≤20 ms |
+| Release identity | #961 | release RED | required gates + immutable release/SBOM/provenance/reproducibility/rollback |
-| PR | Exact observed head | Merge/check state at this snapshot |
-| ---: | --- | --- |
-| #667 | `3bc662d7` | refreshes protected-main and open-queue documentation evidence; base conflict remains to be repaired |
-| #663 | `6fd2f701` | combined Project ontology candidate plus #666's non-default-branch removal of sampled region-coverage arithmetic; base conflict remains to be repaired |
-| #658 | `f007a5ed` | evidence-honest Global Ask cutoff; hosted checks and independent review required |
-| #657 | `2d9b43b7` | TEPP asynchronous lifecycle persistence while unpublished producer work stays unavailable; hosted checks and independent review required |
-| #644 | `ed8d97f3` | native frontend surface code splitting; hosted checks and independent review required |
-| #643 | `7fb4d18c` | shared token-backed status notice; hosted checks and independent review required |
-| #640 | `2d50fa01` | dashboard case metrics and project journeys; base conflict remains to be repaired |
-| #639 | `48065ad1` | restores Running action and Compose contracts; hosted checks and independent review required |
-| #632 | `29aee18d` | graph-fact provenance, public verification, MCP admission, and k6 evidence; hosted checks and independent review required |
-| #631 | `665046dc` (observed parent) | decomposes closed PR #490; this merge refresh advances its head and restarts hosted review evidence |
-| #629 | `0138db5f` | provider-work release and bounded landing reads refreshed onto protected `main`; hosted checks and independent review restarted |
-
-No row above is merge evidence. Immediately before any lifecycle action,
-re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head
-check conclusions. In particular, queued checks are infrastructure state and
-do not transfer evidence from an earlier SHA.
-
-PR #607 first merged as `61fd631c7bb3c57113fd19763c2c43161eeb2824`
-into #606's non-default branch. PR #606 subsequently passed the protected gate,
-so the combined TEPP-consumer and operations-dashboard implementation is now
-on `main`; the still-open TEPP producer PR #237 keeps end-to-end anchor
-acceptance unavailable.
-
-PR #604 was closed unmerged after its exact OIDC repair was composed into #605;
-its green or pending checks are not delivery evidence. PR #482 merged as
-protected-main commit `464ff25002044b9d933c8eefd36c8def7ca0ffd8`
-with package conflict markers, identifying baseline records, and an OIDC
-return-context regression. PR #603 repaired the package/privacy and
-analysis-run transaction defects through protected main at `4f53190b`; the
-OIDC defect remains delivered until #604 or the composed #605 passes the
-protected gate. Protected main is therefore not yet a release candidate.
-
-PR #592 first merged as `3b3af3b4fe9c439354433a43444e05f37ab24ea3`
-into #590's non-default stack base at `2f033ba3`. The complete stack then
-passed the protected gate and #590 merged to `main` as
-`1d1379fc59d9dac6e9c8bfa4812313e3b9e8f3c8`.
-
-PR #521 merged through protected `main` as
-`3797f063b1a7396972a749aa81f23745acccbee1`; it is release evidence and no
-longer part of the open queue. That merge also left a standalone conflict
-marker and duplicated stale tail in `CLAUDE.md`; #594 repaired it through
-protected `main` as `241be2dddf657f854cb8be54fe11d4ef48d37976`.
-
-Protected main now contains the ADR 0109 OIDC return restoration from #605,
-including fragment preservation and storage fallback. The #606 dashboard
-landing must additionally route `?post=` deep links to the Board; that focused
-regression is part of the current candidate and is not delivery evidence yet.
-
-Three systemic gates currently dominate the queue:
-
-1. **Strix visibility lookup failure (org control plane).** PR #600 exact head
- `7580bdc9` failed before scanning because the required-workflow token could
- not resolve this public repository after six API retries. The root repair is
- ContextualWisdomLab/.github#1320 at `3b9b2380`: ordinary PR, push, and
- schedule runs use trusted event visibility; cross-repository dispatch keeps
- authoritative public/private/internal visibility; private and internal
- repositories remain on private-capable providers. The exact head also
- composes the executable fallback contract and classifies bounded NVIDIA
- `ServiceUnavailableError` overload evidence as retryable across configured
- distinct models without weakening exhaustion or vulnerability fail-close.
- A hosted fallback then completed with zero vulnerabilities but was rejected
- because the generic warning gate treated Strix's fallback-model banner and
- a Hugging Face unauthenticated-download notice as provider failures. The
- current head removes only those two exact scanner notices before the
- existing general warning and explicit 429/provider failure checks. The
- current head also clears a foreign NVIDIA/OpenRouter endpoint before a
- direct-OpenAI fallback while retaining an explicitly configured
- direct-OpenAI primary endpoint. The prior full quick-gate harness, overload
- path, 12 visibility-contract tests, and the focused cross-provider endpoint
- contract passed; exact-head hosted revalidation remains pending. It is blocked on
- hosted exact-head gates and independent review, so no repaired
- protected-main Strix runtime evidence exists yet.
-2. **Strix provider unavailability (org control plane).** The central required
- Strix scan on .github#1320 failed when NVIDIA returned `Service temporarily
- overloaded`; the gate correctly failed closed but did not try its configured
- distinct fallbacks because the service-unavailable classifier excluded the
- NVIDIA provider. Exact head `3b9b2380` composes that execution repair and the
- two exact non-fatal scanner-notice exclusions while keeping
- incomplete exhaustion non-passing. This is still an unmerged control-plane
- proposal, not protected-main or downstream runtime evidence.
-3. **Current-head independent approval.** The org merge scheduler requires
- `reviewDecision == APPROVED` plus complete Strix evidence on the exact
- head. Bot review evidence regenerates per push, so any repair push resets
- the review clock by design; this is expected and not a bypass target.
-
-Recent protected-default-branch delivery evidence (squash merges onto
-`main`, newest first):
-
-| PR | Merged (UTC) | Delivered |
-| ---: | --- | --- |
-| #628 | 2026-08-25 12:39 | one-round-trip authorized post filter options without narrowing the complete ABAC-visible set |
-| #627 | 2026-08-25 12:35 | preserved valid k6 lifecycle evidence across setup, scenario execution, and teardown |
-| #468 | 2026-08-25 08:44 | fast-mlsirm, Keyverse, contextual-orchestrator, and TEPP integration boundaries |
-| #493 | 2026-08-25 08:44 | evidence-grounded Event Lineage isolation reasons |
-| #600 | 2026-08-25 08:44 | then-current exact-head product/technical baseline |
-| #605 | 2026-08-25 08:44 | dialog focus order, evidence readability, and OIDC return-context restoration |
-| #608 | 2026-08-25 08:43 | Naruon projection consumed by Workspace Calendar |
-| #603 | 2026-08-25 07:24 | short analysis-run transactions, session advisory locking, package-marker/privacy repair, and provider-work lease release |
-| #602 | 2026-08-25 07:24 | post-detail modal semantics, Escape close, initial focus, and opener restoration; navigation-refocus edge case continues on #605 |
-| #582 | 2026-08-25 07:24 | bounded batched cited-lineage graph fetch |
-| #588 | 2026-08-25 07:23 | named two-axis leftover-map reconstruction and raw-residual identity |
-| #482 | 2026-08-25 07:03 | corroborated SKOS companion organization chips; regressions subsequently tracked above |
-| #601 | 2026-08-25 06:38 | APA 7th PROV-O and PROV-DM references for ADRs 0011 and 0065 |
-| #595 | 2026-08-25 04:39 | audited no-draft import door, nullable updated-at fallback, and event-time import |
-| #484 | 2026-08-25 04:39 | Allen interval relations with deferred FK validation |
-| #383 | 2026-08-25 04:39 | reader-safe OTel diagnostics and service-peer-bounded session metadata |
-| #599 | 2026-08-25 04:28 | raw-residual leftover-map cross-share identity aligned without arbitrary weighting |
-| #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version |
-| #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state |
-| #591 | 2026-08-25 03:32 | prior exact-head product-gap baseline snapshot |
-| #584 | 2026-08-25 03:32 | TEPP topic-lineage consumption boundary grounded in cited temporal models |
-| #581 | 2026-08-25 03:32 | relative-time Ask filtering bound to event time |
-| #596 | 2026-08-25 03:27 | hierarchy/name-resolution deep-work timeouts aligned at 600 seconds |
-| #585 | 2026-08-25 03:27 | raw Global Ask transport exceptions replaced by bounded client-safe detail |
-| #355 | 2026-08-25 02:38 | Naruon calendar projection contract and conformance fixture |
-| #562 | 2026-08-24 02:05 | parameter-free classic RRF; deleted the last hand-picked fused score |
-| #561 | 2026-08-24 01:47 | knowledge-graph precedence/hierarchy relation classification and layout order |
-| #555 | 2026-08-24 01:29 | per-channel score breakdown persisted on `post_lineage_edge.channel_scores` (ADR 0195) |
-| #559 | 2026-08-24 01:26 | deleted `DEFAULT_CHANNEL_WEIGHTS` hand-picked fallback |
-| #549 | 2026-08-24 00:43 | clamped embedding cosine into `[0, 1]` instead of remapping from `[-1, 1]` (ADR 0190) |
-| #548 | 2026-08-24 00:37 | mid-reconstruction provider failure maps to an explicit unavailable state |
-| #544 | 2026-08-24 00:27 | fusion weights accepted only via fast-mlsirm estimation |
-| #538 | 2026-08-23 23:39 | real embeddings wired into the Event Lineage text channel |
-
-This documentation is owned by protected `main` again: the #426 stack landed,
-so hidden-stack merges (#494, #497, #499, #505, #509 into unprotected parent
-branches) are historical context only and no longer gate anything.
-
-The current protected-`main` and exact #507 trees are clean of the private
-runtime source-table identifier present in the closed #506 head and older
-public history. Do not reproduce or hint at its value. Historical remediation
-requires the ADR 0001 incident process and security/privacy-owner coordination;
-never force-push or delete evidence ad hoc.
-
-The Grok durable hourly loop and the central thin GitHub Actions caller
-ContextualWisdomLab/.github#1259 (minute 4, `pr-review-fix-scheduler.yml`)
-both target this repository. Do not add a LineageWeave-local duplicate
-workflow. ContextualWisdomLab/.github#1258 merged at exact head `897819c4` to
-repair the pnpm/coverage-evidence workflow; newly created exact PR heads must
-still prove the runtime behavior because merged workflow source alone is not
-check evidence.
-
-Figma design-system boundary (ADR 0002): File ID `1Su3lDRmiZdcUs47t1QwIX`.
-The sanitized file now contains synthetic Event Lineage desktop (`5:14`) and
-mobile (`5:15`) frames with graph direction, event dates, an inference
-boundary, and exact fused-score evidence. Do not copy source-organization
-content into this repository. Storybook remains the executable scene and
-edge-case inventory for repeated web objects; rendered code-to-Figma parity
-still requires same-viewport browser comparison on an exact candidate head.
-
-## 2. User-visible capability baseline
-
-Substantially present on protected `main`:
-
-- PostgreSQL-backed import, normalized provenance, cutoff-aware analysis runs,
- source revisions, lineage reconstruction, and explicit unavailable states.
-- Authenticated workspace navigation, post detail, localized summaries, 5W1H,
- R&R/Keyman, evidence citations, chat, organization hierarchy, and lineage DAG
- (`frontend/src/LineageDag.tsx` is on `main`; the old “DAG view missing”
- baseline entry is stale).
-- Semantic paragraph/list/table/image-region units that preserve the source
- representation and provenance instead of flattening it into one body string.
-- FJA→I/O-Psychology semantic layer (ADR 0251): the published DOT/FJA
- Data/People/Things worker functions (ADR 0232) project into disjoint
- cognitive, affective, and behavioral constructs with APA 7th anchors,
- SHACL validation, and a deterministic typed read model
- (`lineageweave/iopsy_taxonomy.py`); no fitted weight or O*NET/ADR 0248
- crosswalk is asserted (ADR 0145).
-- Contextual-orchestrator boundaries for adjudication, extraction, summaries,
- chat, embeddings, and VISION; null channels remain unavailable and are
- dropped from score fusion.
-- W3C PROV-O projection through normalized provenance tables, with the
- knowledge graph retained as an explicit navigation projection.
-- Keyverse/Keycloak OIDC, RankWeave fusion port, TEPP measurement client,
- ThreadWeave tree assembly.
-
-These statements describe source capability, not authenticated production
-corpus acceptance or protected release.
-
-## 3. Historical open-PR inventory (superseded by §1)
-
-Heads below are queue evidence captured at snapshot time; recheck SHA,
-checks, unresolved threads, and independent approval immediately before any
-merge claim. Do not self-approve, force-push, or transfer stale review
-evidence across heads. The org merge scheduler merges only when
-`reviewDecision == APPROVED` on the exact head and Strix evidence is complete.
-
-### 3.0 Shared systemic gate
-
-| Gate | Evidence | Durable repair |
-| --- | --- | --- |
-| Strix provider unavailability | `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` and `openai-direct/gpt-5.6-luna` failed authoritatively across unrelated heads | ContextualWisdomLab/.github#1263 at `ab3d7645` proposes executable Azure/cross-provider fallbacks but remains open/conflicting; repair that branch without weakening the required gate |
-| ADR 0109 login repair debt | Eight branches cut from the pre-repair base carried the unauthenticated `AdminPanel` + unused-OIDC-helper `tsc -b` failure | Same verified two-line repair applied to #521, #522, #552, #553, #554, #556, #558, #560 during this loop; frontend lint/test/build verified locally |
-
-### 3.1 Workspace root and product surfaces
-
-| PR | Head | Intent | Notes |
-| ---: | --- | --- | --- |
-| #258 | `f0b5234d` | Workspace evidence board and source-grounded ontology surface (root stack) | Largest surface; historical CHANGES_REQUESTED is stale relative to current head |
-| #349 | `bef4a858` | Bounded ontology and provenance explorer (v2.13.0) | Issue #341 |
-| #355 | `2f3f308c` | Naruon event projection contract | Issues #336/#338 |
-| #387 | `5ef0f2e6` | Persist and explain Event Lineage channel evidence | Issue #274 |
-| #405 | `ec62d9f0` | Persisted image-region locations (v2.12.8) | VISION region provenance |
-| #484 | `878c4a87` | Allen interval relations on Event Lineage edges (v2.15.0) | Temporal modeling; Allen (1983) |
-| #490 | `d0cad030` | Wire remaining ADR 0133–0137 surfaces | Consolidated product stack incl. Knowledge Graph token repair |
-| #493 | `499c8b1b` | Name Event Lineage isolation reasons (v2.16.0) | Honest unavailable/failed states |
-
-### 3.2 SKOS organization aliases and leftover-map family (stacked)
-
-| PR | Head | Intent |
-| ---: | --- | --- |
-| #480 | `f18b421d` | Bind corroborated SKOS org aliases to one catalog row |
-| #482 | `c38c08d6` | Corroborated SKOS companion caption on organization chips (v2.14.0) |
-| #481 | `32944979` | Persist leftover interaction-map coordinates (v2.12.7) |
-| #485 | `dcaa6320` | Leftover pair clicks land on the named Post quality criterion (v2.12.8) |
-| #518 | `3117823f` | Name leftover complete-case coverage (v2.12.17) |
-| #519 | `31c150c8` | Persist leftover-map axis share on period reports (v2.12.16) |
-| #521 | `40677c75` | Leftover pairs on the grouping comparison strip (v2.12.17) |
-| #522 | `9be3712e` | Leftover-map distances on two Gabriel axes (v2.12.18) |
-| #535 | `1fb5d69a` | Name leftover-map unexplained leftover (v2.12.26) |
-| #537 | `9a639554` | Name leftover-map unexplained share (v2.12.27) |
-| #539 | `740629d0` | Name leftover-map explained share (v2.12.28) |
-| #563 | `740d50f3` | Name leftover-map cross share (v2.12.29) |
-| #564 | `ac5de72a` | Name leftover-map reconstruction share (v2.12.30) |
-
-The leftover-map naming series (#518–#564) is a stacked ladder of honest
-leftover-pair labeling increments; merge in ascending order once each exact
-head clears gates.
-
-### 3.3 Repairs and operability
-
-| PR | Head | Intent |
-| ---: | --- | --- |
-| #393 | `4ddd3a83` | Detach provider parse error context (honest orchestrator failure) |
-| #394 | `cf9505b7` | Preserve source indentation evidence for adjudication |
-| #434 | `01d6cca5` | Wire adjudication client into corpus-wide rebuild (issue #289) |
-| #541 | `3d93ea9b` | Bootstrap repo-root sys.path in operator scripts |
-| #546 | `d210c20c` | Strip Keycloak OIDC callback params from post share links |
-| #547 | `fb7fe2db` | Shorten orchestrator healthcheck retry budget |
-| #552 | `89000280` | Footer text contrast passes WCAG 1.4.3 AA |
-| #553 | `e5152f5c` | `.post-meta` contrast in both themes |
-| #554 | `689e42e4` | Event Lineage DAG node marks get a 24×24 px hit target |
-| #556 | `21cf9991` | Citation chip grows to a 24px touch target |
-| #558 | `91dd1bfc` | Bare loading text exposed as live regions |
-| #560 | `59b769e3` | Secondary details/summary toggles sized to `--size-control-min` |
-
-### 3.4 Integration and measurement boundary
-
-| PR | Head | Intent |
-| ---: | --- | --- |
-| #417 | `cb08377c` | TEPP topic-lineage consumption boundary (TRSL-TM + CHRONOS/TDT) ADR |
-| #468 | `228f13dd` | Bind fast-mlsirm, Keyverse, orchestrator, and TEPP integration tests |
-| #258-family measurement note | — | GRM/GPCM/CAT/FIPC parameter recovery (#451–#454) landed earlier; true-parameter RMSE remains the acceptance bar |
-
-### 3.5 Documentation
-
-| PR | Intent |
-| ---: | --- |
-| #565 | Sync AGENTS.md / CLAUDE.md with accepted ADR boundaries |
-| this file | Non-identifying gap baseline refresh (ADR 0001) |
-
-Closed as superseded during this loop: #368 (baseline rewrite superseded by
-this file per §3.5 of the prior snapshot).
-
-## 4. Open issues (complete live queue; product acceptance remaining on `main`)
-
-| Issue | User-visible gap | Active PR |
-| ---: | --- | --- |
-| #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge |
-| #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work |
-| #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack |
-| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | #658; still open and not protected-main evidence |
-| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | #632 preserves internal provenance; public verification acceptance remains open |
-| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #657 consumer lifecycle; executable producer route remains unavailable |
-| #280 | Full project-lifecycle history and handover intervals | #640 adds case/project journeys and #663 adds evidence-backed Project exploration; authoritative lifecycle reconciliation remains #284 |
-| #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed |
-| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | #704 recreates the provider-side contract on current `main` without arbitrary fusion weights; #343 remains only a non-default-stack merge and #355 is a distinct calendar contract |
-| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required |
-
-## 5. Open product and technical gaps
-
-| Gap | Current evidence | Acceptance requirement |
-| --- | --- | --- |
-| Protected release | 12 open PRs at snapshot, all targeting `main` with normal auto-merge enabled. None has the required independent approval, and running checks on #631/#632/#663 are not treated as blockers for safe work on other PRs. #666's merge into the non-default #663 branch is not protected-main delivery | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA |
-| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention |
-| Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior |
-| Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push |
-| Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc |
-| Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence |
-| Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved |
-| Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing |
-| Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts |
-| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility, label-bound, and temporal test-double regressions are repaired. #666's heuristic removal is composed into this parent but is not separately protected-main evidence. #640 separately adds project journeys without claiming authoritative lifecycle status | Combined #663 must pass exact-head checks and independent approval before protected merge. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence |
-| Voice primary history | Protected `main` `bbb19192` includes ADR 0252 / #761 (migration 0243, GiST primary-period exclusion, `clock_timestamp()` after the source-row lock, API/ontology half-open cutoff SQL). v2.22.1 adds synthetic PostgreSQL integration tests for A → B → A at before/between/after cutoffs, concurrent primary updates, additional-assignment close, and 0237→0243 trigger replay. This is not yet protected-main evidence | Land the live-test slice through the protected gate with independent exact-head APPROVE; close #748 only after that protected delivery |
-| Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface |
-| Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding |
-| Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired |
-| SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound |
-| Event Lineage evidence | Channel evidence and Allen relations live on #387 / #484 | Persist channel scores, explain them in the popup, never invent a fused score |
-| Scientific measurement | Durable accepted TEPP receipts and LineageWeave #614's exact accepted snapshot/cutoff/run/pair-count consumer are protected; TEPP #237 remains open, so no registered producer artifact exists yet. #387 removes inferred/default persistence weights, but several older reconstruction tests still pass hand-authored numeric dictionaries that are not estimator evidence | Land TEPP #237 through its protected gate, then replace remaining reconstruction-test constants with provenance-bearing fast-mlsirm estimates over synthetic fixtures. Retain true-parameter RMSE recovery as the acceptance bar |
-| Asynchronous authorization | Protected `main` rebuilds Global Ask worker scope after the bearer token leaves the request; #468 now persists exact Keyverse organization/process-unit scope in 3NF child tables and intersects it with current affiliations | Land #468 through the protected gate; prove a second affiliation and a revoked process unit cannot widen delayed-job evidence |
-| Planned-facility intent | Planned-facility relationship intent remains only on closed, unmerged #490; earlier stack-only merges were not protected delivery | Recreate the evidence-backed slice on a current base and land through protected `main` before a release claim |
-| Accessibility and responsive UX | #602 delivered base post-detail modal semantics; #605 adds selected-post refocus, collapsed/hidden/inert/CSS-invisible focus exclusion across both modal types, readable evidence separators, focused tests, and desktop/mobile Storybook screenshots | Land #605 through the protected gate, then complete screen-reader and authenticated Playwright acceptance on the exact release head |
-| Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release |
-| Frontend delivery performance | #644 implements a native dynamic-import boundary for conditional workspace surfaces and retains accessible loading/error states; exact-head checks passed but the PR is not protected-main evidence | Merge #644 normally, rebuild the protected-main production bundle, and retain the measured chunk inventory rather than raising the warning limit |
-| External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, DiskSage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence |
-| Naruon email/project lineage | #704 provides a strict store-agnostic v1 contract, opaque evidence references, observed/inferred truth separation, knowledge-cutoff admission, and explicit unavailable states. Inferred edges require an injected provenance-bearing fast-mlsirm estimate; no local default weight exists | Merge #704 through protected `main`, publish an immutable attested artifact, then enable the Naruon consumer only against that released version and its contract fixtures |
-| MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there |
-| Accelerator runtime ownership | ADR 0076/0208 already prohibit local model and mathematical ownership; ADR 0237 now defines MLX as a native orchestrator-side service and TEPP/fast-mlsirm CUDA/OpenCL/CPU profiles as scientific-compute-owner deployments, so LineageWeave Compose remains device-neutral. RankWeave remains the dependency-free Python retrieval-fusion/evaluation owner behind its published contract | TEPP and fast-mlsirm must publish deterministic CPU recovery plus conformance evidence for every advertised CUDA/OpenCL profile; contextual-orchestrator must prove native MLX availability through its provider-neutral health/contract boundary. LineageWeave accepts only versioned, provenance-bearing envelopes and fails closed when the owner is unavailable |
-| Product contract authority | The current LineageWeave PRD records exact-case ecosystem authorities. TEPP, fast-mlsirm, keyverse, ThreadWeave, and RankWeave PR #41 have standalone PRDs; RankWeave's remains unmerged. contextual-orchestrator, disksage, and wardnet still rely on product/architecture documents, and naruon has only a scoped Topic Intelligence PRD | Keep ADRs normative, preserve canonical repository case in machine references, land the pending PRDs, and add standalone PRDs in each remaining owning repository before cross-product release claims exceed its documented boundary |
-| Release quality | PR #660 is now on protected `main`; its pre-merge full Python suite passed 1,352 tests with 17 skips, but release-wide frontend, Storybook, security, browser, and runtime acceptance remain unproven on one exact protected head | Repository-wide coverage, docstrings, Storybook, security, browser, and release evidence on one exact head |
-| PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read |
-| Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration |
-
-### 5.1 Closed PR #490 decomposition (issue #611)
-
-Protected `main` at `04e6b610` and the three open PRs present during the initial
-decomposition were rechecked; the later audit snapshot above includes #631
-itself as the fourth open PR. Protected `main` contains none of PR #490. That PR remains
-closed, unmerged branch evidence; its ADR 0133–0137 files are not normative and
-its 321-file tree must not be replayed. Current-main code and schema searches
-give this delivery matrix:
-
-| Closed-branch decision | Current-main classification | Smallest remaining delivery |
-| --- | --- | --- |
-| ADR 0133 source-reference research | Partial foundation: protected `main` has the self-hosted SearXNG relation-verification client and fail-closed configuration, but it verifies an already extracted relation. It has no source-unit/image-region lead, cited-resource retrieval, claim judgment, or normalized research citation workflow | One post-scoped lead-to-citation slice that reuses the self-hosted SearXNG search boundary, adds public-target SSRF/redirect rejection for result retrieval, and judges through contextual-orchestrator with explicit unavailable outcomes |
-| ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states |
-| ADR 0135 kind/status-exact analysis actions | Partial: protected `main` has kind-aware start/retry controls plus normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts; it does not contain the closed branch's unified guidance component or its full kind × status interaction inventory | Test the current run-kind/status matrix first, then add only a proven missing state/control pair rather than copying the closed-branch function |
-| ADR 0136 per-post Ask history | Partial: `post_chat_result` / `post_chat_citation`, the authorized post Chat API, and its linear exchange history are on protected `main`. Account-and-post-scoped sessions, ordered turns, list/select/new controls, and batched citation reauthorization are not | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before adding the conversation picker |
-| ADR 0137 cross-post customer identity | Partial foundation: protected `main` preserves source customer hints and has corporate-catalog unique/miss/tie safeguards, but it has no normalized cross-post customer-identity judgment, supporting-post binding, or corporate-name-history workflow | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint |
-
-This matrix satisfies only #611's current-main inventory step. Issue #611
-remains open: every unmet criterion above still needs a focused regression test
-and exact-head current-main implementation PR before its acceptance criteria
-are satisfied. No stale check, review, or implementation is transferred from
-#490.
-
-## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited)
-
-Each item needs a Storybook scene, an edge-case story, and an automated check
-before a commercial release claim. Figma File ID `1Su3lDRmiZdcUs47t1QwIX`.
-
-| Dimension | Current | Gap |
-| --- | --- | --- |
-| Accessibility | Partial labels/roles on board, popup, login | WCAG 2.2 AA on login, board, popup, Ask, calendar, admin; focus order; live regions |
-| Touch & Interaction | Click-first popup and lists | 44px targets, swipe/escape to dismiss popup, no hover-only actions |
-| Performance | Board caps and hint render limits exist | Interaction-to-next-paint on board search, DAG, Ask; no N+1 (#358) |
-| Style Selection | Korean UI standards merged (#347) | Tokenized light/dark; Anti-Slop-UI density; no decorative noise |
-| Layout & Responsive | Desktop popup shell | 402px-class phone layout; stacked GNB; readable DAG |
-| Typography & Color | Badge tokens extracted | Contrast on badges, links, error/status; no raw hex in components |
-| Animation | Minimal | Reduced-motion; no blocking animation on evidence open |
-| Forms & Feedback | Login, Ask, tickets, admin brand | Inline validation, next-action copy, unavailable vs failed distinction |
-| Navigation Patterns | Board / customers / calendar / Ask / admin | Deep-link post + OIDC return URL (#426); bookmarkable Ask |
-| Charts & Data | Period reports, leftover pairs, Rankings, DAG | Honest empty/unavailable; no invented theta; Storybook chart states |
-
-## 7. Ecosystem leverage order
-
-Reuse before rebuild. Consume these ContextualWisdomLab packages in this order
-of leverage; open connector PRs there when the defect is upstream:
-
-1. **contextual-orchestrator** — every LLM/VISION/embedding call (Fugu / Conductor / TRINITY routing). Never a raw provider SDK.
-2. **Keyverse** — OIDC issuer, JWKS, tenant principals.
-3. **RankWeave** — fused scores and rankings; never invent a fused score or theta.
-4. **TEPP** — calibrated measurement; persist receipts; no local reimplementation.
-5. **fast-mlsirm** — GRM/GPCM/CAT/FIPC recovery tests (#451–#454) must stay true-parameter RMSE.
-6. **ThreadWeave** — tree assembly.
-7. **Naruon** — calendar and email/project lineage projection (#336, #338, #355).
-8. **DiskSage / wardnet** — storage and network policy as needed.
-9. **ContextualWisdomLab/.github** — required review workflows (OpenCode, Strix, Noema) and the LineageWeave hourly caller (#1259). If stacked PRs miss central review or coverage-evidence fails on pnpm 9 (`--trust-lockfile` is pnpm 11.3) or a missing Vitest coverage provider, fix the org workflow (#1258), not a local bypass.
-
-## 8. Public ontology publication boundary
-
-- PR #426 publishes fragment-addressable HTML, byte-identical Turtle,
- isomorphic JSON-LD and N-Triples, the PROV-O support profile, and a
- source-digest manifest from the authoritative ontology.
-- Pull requests validate only. Only protected `main` may publish, and the
- generated-directory marker, linked-IRI, duplicate-fragment, symlink, and
- source-overlap checks fail closed.
-- The lowercase knowledge-graph namespace and repository-case support-profile
- namespace remain distinct until issue #372 delivers a versioned migration
- and compatibility decision; this publication PR rewrites neither identity.
-- Until the protected deployment and exact URL checks succeed, the public
- ontology endpoint remains unavailable and must not be represented as live.
-
-## 9. Evidence boundaries
-
-- Never add a real record, title, name, identifier, screenshot, log, benchmark
- artifact, or documentation example to this repository.
-- Attendance or co-occurrence is not responsibility, project, customer, or
- affiliation evidence. Preserve uncertainty and provenance.
-- Missing transport, model capability, accepted envelope, or persistence is
- unavailable or failed evidence, never a placeholder result.
-- Local green tests, bot statuses, auto-merge, and warning-only checks do not
- prove a protected merge.
-- Re-fetch base/head SHAs, checks, review threads, approvals, rulesets, and the
- merge SHA immediately before any lifecycle claim.
-- Do not self-approve. Independent OpenCode / Strix / Noema review is required.
-- Do not force-push. Do not treat GitHub Checks duration as a blocker; repair
- the failing check instead.
-- `COPILOT_GITHUB_TOKEN` is not used.
-
-## 10. Next acceptance loop (autonomous merge order)
-
-Process every open PR in ascending number order, considering leverage; for
-each: check reviews → repair → re-verify Checks → merge → continue. Checks and
-review latency are never blockers — keep working while they settle.
-
-1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile
- open .github#1263, and land the atomic hourly LineageWeave caller in open
- .github#1288 only through their protected gates.
-2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657,
- #658, #659, #660, and #663 only after each exact head shows terminal green
- required checks plus current-head independent approval. Treat #666's
- non-default-branch merge only as part of #663's combined candidate and
- collect all protected evidence on #663's exact head.
-3. While hosted checks or independent reviews wait, resume user-visible gaps
- from §5 in leverage order:
- external semantic verification (#272), Naruon calendar (#355/#336), and
- authenticated operations/ontology publication acceptance. Event Lineage
- evidence shipped in merged PR #387 and closed issue #274 is not an open gap.
-4. Rename remaining `[Buyer Gap]` issue titles to neutral product-object
- naming per repository convention (no "Buyer" for internal objects).
-5. Keep psychometric tests as true-parameter recovery (RMSE); never fixture
- tautologies, invented theta, or hand-authored numeric weights. Remove
- weights from tests that do not exercise fusion; fusion tests must consume
- provenance-bearing fast-mlsirm estimates over synthetic fixtures.
-6. Run frontend lint/test/build/Storybook, backend tests, and authenticated
- browser/accessibility checks on the exact candidate release head.
-7. Fix only evidence-backed failures and repeat the protected merge gate.
-8. Refresh this file each loop with the exact queue state.
-
-## 11. Spec pointers (derive, do not fork)
-
-- Product/architecture: `ARCHITECTURE.md`, `AGENTS.md`, `CLAUDE.md`
-- Research grounding: ADR 0084, `docs/lineage-bi-research-notes.md`
-- Demo identity: ADR 0001
-- Figma boundary: ADR 0002 (File ID `1Su3lDRmiZdcUs47t1QwIX`)
-- Orchestrator / paper-grounded models: ADR 0015, ADR 0076 (Fugu, TRINITY, Conductor)
-- Ontology / PROV-O / SKOS: ADR 0004, ADR 0011, issue #372
-- Analysis runs / TEPP: ADR 0013–0023, issue #79 / #277
-- Calendar / Naruon: issues #336 / #338, PR #355, operator consumption v2.17.0
-- Ask Agent: issues #269–#272, #358–#363
-
-Citations in doctoring and ADRs use APA 7th. Do not invent a heuristic where
-the papers leave the decision undecided.
-
-## 12. Delivery snapshot (2026-08-27)
-
-Fresh merges on protected `main`, verified from PR lifecycle state and
-post-merge reruns (not transferable evidence for later heads):
-
-| PR | Delivery | Governing ADR / reference |
-| ---: | --- | --- |
-| #643 | Shared StatusNotice (ADR 0220): success/unavailable/retry states, WorkspaceCalendar auth-unavailable copy, 5-locale i18n; CI Full suite 22m54s green | ADR 0220 |
-| #644 | Native workspace surface split: 9 conditionally rendered components as lazy() dynamic imports behind a SurfaceBoundary error boundary; build emits 9 chunks (1.5-37 kB), main bundle 543 kB; 470 frontend tests, tsc, Storybook green | — |
-| #762 | Evidence-bound project history (ADR 0243): /api/projects/{key}/history endpoint, project_history.py projection, fetchProjectHistory client, standalone ProjectHistoryTimeline component; supersedes #668 (3-way merge kept only the additive +2279/-0, dropping the branch's 8k shared-file reverts; popup UI hookup deferred as a scoped follow-up) | ADR 0243 |
-| #763 | Live-PostgreSQL A→B→A Voice history validation (ADR 0252) proving effective_from/effective_to interval replacement across repeated primary-Voice imports | ADR 0252 |
-| #764 | Test-only coverage lift: observability 78%→96%, post_summary 77%→89%, claim_verification 86%→99%; package line coverage 93.5%→95% (484→371 missing); 1651 Python tests green | — |
-| #761 | Temporal imported-primary Voice history (ADR 0252): migration 0243 (`effective_to` + GiST primary-period exclusion + synchronize trigger), refined 0237 `least()` effective_from backfill, `effective_from/effective_to` dataclass/export + `coalesce($2,$3)` cutoff predicate. Completes the half-shipped main layer that queried `voice.effective_to` against a missing column. CI Full suite 19m13s green | ADR 0252 |
-| #629 | Provider work released before embedding pool bound; landing reads bounded (k6-verified concurrency); merged with strix-only infra timeout (Full suite + all other gates green) | — |
-| #750 | Leftover-map unexplained leftover share persisted (`report_leftover_map_unexplained_share`, share `s = U² / R²`) | ADR 0233 |
-| #749 | Authorized job-family/job-series import snapshots (`0223_authorized_job_architecture`) | ADR 0263 |
-| #759 | ***Promoted** the ONET rating-store stack to `main`: migrations 0222/0223, authenticated rating/rating-sources/rating-occupations endpoints, `OccupationRatingProfile` UI + stories, rating client functions, import scripts, ADR 0252–0263 references. Semgrep SQLi nullified by PL/pgSQL `format(%I/%L)` DDL + documented `nosemgrep`; 1583 Python + 447 frontend tests green | ADR 0257–0263 |
-| #747 | Current product and MCP manuals (`docs/manuals/*`, contract tests) | ADR 0118-family |
-| #754 | Customer-actionable copy and ADR 0237 accelerator runtime boundary; share/bookmark/verification call sites reworded and ko/zh/ja/vi translations completed after review | ADR 0237 |
-| #700 | Source conversation-turn evidence ingestion (`0233_source_conversation_turn_evidence`, choke/adjacency resilience) | ADR 0238 |
-| #658 | Optional Global Ask knowledge cutoff honoring `source_post_revision` cover | ADR 0216 |
-| #632 | Graph-fact source provenance preserved through MCP streaming + verified psql-parity migration fixture | ADR 0166 |
-| #742 | Evidence-bound product-operations relations (stack base) | ADR 0235 |
-| #743 | Imported occupation-rating source catalog (stack base) | ADR 0260 |
-| #745 | Occupation catalog title filter (stack base) | ADR 0262 |
-| #746 | Rating-source occupation selector (stack base) | ADR 0261 |
-| #740 | Occupation rating evidence view (stack base) | ADR 0259 |
-| #720 | Cancel stale test runs on PR close | — |
-| #716 | Prioritized evidence-bound operations backfill | — |
-| #711 | Pinned validated structured-workflow runtime | — |
-| #704 | Current-main external lineage contract publication | — |
-
-The ONET rows stacked into base branches (#743/#745/#746/#740/#732) reached
-`main` together through the #759 promotion; their per-base merge records are
-historical evidence only. The job-architecture artifact ship originally via
-#749 is now re-verified on `main` from the promotion.
-
-### 2026-09-07 — #825 current-parent reconstruction candidate
-
-Exact parent `#824@499d653ed6e9206249e3f3a07518ad3fc01f14bd` lacks the grouping-comparison incomplete-item note while carrying authorization-filtered persisted coverage. ADR 0294 / v2.51.0 adds that buyer-visible read-model presentation and regression. Candidate evidence is not protected-main/release evidence; current-head browser/a11y, canonical eight-locale ledger consumption, independent review, and normal protected merge remain outstanding.
-
-### 2026-09-07 — #826 exact-parent reconstruction candidate
-
-Exact parent `#825@b73b10e3079e77f3e62235b2b709dc8a3f450292` omits persisted `R̂` from grouping-comparison pair rows. ADR 0295 / v2.52.0 restores that valid read-model delta and repairs the historical accessibility defect by carrying the label/value in the button accessible name. Candidate evidence is not protected-main/release evidence; current-head browser/screen-reader/a11y, canonical eight-locale ledger consumption, independent review, and normal protected merge remain outstanding.
-
-### 2026-09-07 — #827 exact-parent reconstruction candidate
-
-Exact parent `#826@66a7750a10ad0e9526716d382707f99528a75d90` omits persisted grouping-comparison explained-leftover share. ADR 0296 / v2.53.0 restores that valid delta and fixes its historical accessible-name defect. Candidate evidence is not protected-main/release evidence; current-head browser/screen-reader/a11y, canonical eight-locale ledger consumption, independent review, and normal protected merge remain outstanding.
+This baseline records unresolved authority; it must not be used to infer a merge, approval, release, or GREEN state that exact protected evidence does not show.
diff --git a/frontend/package.json b/frontend/package.json
index 4f0158ad8..73f45e5b4 100644
--- a/frontend/package.json
+++ b/frontend/package.json
@@ -11,7 +11,8 @@
"test": "vitest run",
"e2e": "playwright test",
"storybook": "storybook dev -p 6006",
- "build-storybook": "storybook build"
+ "build-storybook": "storybook build",
+ "test:storybook:browser": "playwright test --config playwright.storybook.config.ts"
},
"dependencies": {
"oidc-client-ts": "^3.5.0",
diff --git a/frontend/playwright.storybook.config.ts b/frontend/playwright.storybook.config.ts
new file mode 100644
index 000000000..74441206c
--- /dev/null
+++ b/frontend/playwright.storybook.config.ts
@@ -0,0 +1,28 @@
+import { defineConfig, devices } from "@playwright/test";
+
+/** Browser acceptance for the already-built Storybook artifact. */
+export default defineConfig({
+ testDir: "./storybook-e2e",
+ testMatch: "**/*.pw.ts",
+ fullyParallel: false,
+ forbidOnly: !!process.env.CI,
+ retries: process.env.CI ? 1 : 0,
+ workers: 1,
+ reporter: [["list"]],
+ use: {
+ baseURL: "http://127.0.0.1:6006",
+ trace: "retain-on-failure",
+ },
+ projects: [
+ {
+ name: "chromium",
+ use: { ...devices["Desktop Chrome"], hasTouch: true },
+ },
+ ],
+ webServer: {
+ command: "python3 -m http.server 6006 --directory storybook-static",
+ url: "http://127.0.0.1:6006",
+ reuseExistingServer: false,
+ timeout: 120_000,
+ },
+});
diff --git a/frontend/src/App.test.tsx b/frontend/src/App.test.tsx
index fb9e4befd..8f5705ef6 100644
--- a/frontend/src/App.test.tsx
+++ b/frontend/src/App.test.tsx
@@ -4203,9 +4203,9 @@ describe("App, authenticated", () => {
"Leftover map dropped 0 incomplete criteria",
);
const coverageCaption = screen.getByLabelText("Leftover map coverage");
- const closestPair = screen.getByRole("button", { name: /open leftover closest pair: public post/i });
+ const closestPair = screen.getByRole("button", { name: /^closest leftover: public post · sales-lead /i });
const farthestPair = screen.getByRole("button", {
- name: /open leftover farthest pair: specification revision requested/i,
+ name: /^farthest leftover: specification revision requested · negative /i,
});
expect(closestPair).toHaveTextContent("Closest leftover: Public post · sales-lead");
// Leftover-map coordinates are present, so they name the next action
@@ -4223,7 +4223,7 @@ describe("App, authenticated", () => {
expect(closestPair).toHaveTextContent("R̂ +0.25");
expect(closestPair).toHaveTextContent("ξ (+0.50, +0.10) ζ (+0.50, −0.02)");
expect(closestPair).toHaveTextContent("d 0.12");
- expect(closestPair).toHaveAccessibleName("Open leftover closest pair: Public post · sales-lead");
+ expect(closestPair).toHaveAccessibleName(/^Closest leftover: Public post · sales-lead /);
expect(farthestPair).toHaveTextContent("Farthest leftover: Specification revision requested · negative");
expect(farthestPair).toHaveTextContent(
"Leftover map places this post at ξ (+0.90, +0.80) and the criterion at ζ (−0.70, −0.40) after IRT main effects. Open this post to read negative.",
@@ -4438,7 +4438,7 @@ describe("App, authenticated", () => {
render();
await userEvent.click(
- await screen.findByRole("button", { name: /open leftover closest pair: public post/i }),
+ await screen.findByRole("button", { name: /^closest leftover: public post · sales-lead /i }),
);
await waitFor(() => expect(screen.getByText("The full body text.")).toBeInTheDocument());
expect(await screen.findByRole("heading", { name: "Post quality (IRT)" })).toHaveFocus();
@@ -4454,7 +4454,7 @@ describe("App, authenticated", () => {
await userEvent.click(screen.getByRole("button", { name: "Close" }));
await userEvent.click(
await screen.findByRole("button", {
- name: /open leftover farthest pair: specification revision requested/i,
+ name: /^farthest leftover: specification revision requested · negative /i,
}),
);
await waitFor(() =>
diff --git a/frontend/src/components/LeftoverPairList.accessibleName.test.tsx b/frontend/src/components/LeftoverPairList.accessibleName.test.tsx
new file mode 100644
index 000000000..a562e701b
--- /dev/null
+++ b/frontend/src/components/LeftoverPairList.accessibleName.test.tsx
@@ -0,0 +1,246 @@
+import { render, screen } from "@testing-library/react";
+import userEvent from "@testing-library/user-event";
+import { describe, expect, it, vi } from "vitest";
+import type { LeftoverPair } from "../api";
+import { LeftoverPairList } from "./LeftoverPairList";
+
+const PAIR: LeftoverPair = {
+ pair_kind: "closest",
+ post_id: "post-demo-public",
+ post_title: "Public post",
+ criterion_code: "sales_lead_quality",
+ leftover_distance: 0.12,
+ leftover_residual: 0.4,
+ observed_response: 2.4,
+ expected_response: 2.0,
+ leftover_map_rank: 1,
+};
+
+const ACTION_EVIDENCE_CASES: Array<[string, Partial, string]> = [
+ [
+ "rank-only",
+ { observed_response: null, expected_response: null, leftover_map_rank: 2 },
+ "rank 2",
+ ],
+ ["observed/expected", { leftover_map_rank: null }, "Y 2.40"],
+ ["unexplained", { leftover_map_unexplained: 0.05 }, "U +0.05"],
+ [
+ "reconstruction",
+ { leftover_map_unexplained: 0.05, leftover_map_reconstruction: 0.35 },
+ "R̂ +0.35",
+ ],
+ [
+ "cross share",
+ {
+ leftover_map_unexplained: 0.05,
+ leftover_map_reconstruction: 0.35,
+ leftover_map_cross_share: 0.13,
+ },
+ "0.13",
+ ],
+ [
+ "unexplained share",
+ {
+ leftover_map_unexplained: 0.05,
+ leftover_map_reconstruction: 0.35,
+ leftover_map_cross_share: 0.13,
+ leftover_map_unexplained_share: 0.23,
+ },
+ "0.23",
+ ],
+ [
+ "explained share",
+ {
+ leftover_map_unexplained: 0.05,
+ leftover_map_reconstruction: 0.35,
+ leftover_map_cross_share: 0.13,
+ leftover_map_unexplained_share: 0.23,
+ leftover_map_explained_share: 0.76,
+ },
+ "0.76",
+ ],
+ [
+ "coordinates",
+ {
+ leftover_map_unexplained: 0.05,
+ leftover_map_reconstruction: 0.35,
+ leftover_map_cross_share: 0.13,
+ leftover_map_unexplained_share: 0.23,
+ leftover_map_explained_share: 0.76,
+ leftover_map_person_axis_1: 0.5,
+ leftover_map_person_axis_2: 0.1,
+ leftover_map_item_axis_1: 0.5,
+ leftover_map_item_axis_2: -0.02,
+ },
+ "ξ (+0.50, +0.10)",
+ ],
+];
+
+function criterionLabel(code: string): string {
+ return code === "sales_lead_quality" ? "sales-lead" : code;
+}
+
+function occurrences(value: string, token: string): number {
+ return value.split(token).length - 1;
+}
+
+function accessibleNameFor(overrides: Partial = {}): string {
+ render(
+ ,
+ );
+ return (
+ screen
+ .getByRole("button", { name: /^Closest leftover: Public post · sales-lead / })
+ .getAttribute("aria-label") ?? ""
+ );
+}
+
+describe("LeftoverPairList accessible action name", () => {
+ it("starts with the rendered label and carries each finite evidence value once", async () => {
+ const onSelectPost = vi.fn();
+ render(
+ ,
+ );
+
+ const action = screen.getByRole("button", {
+ name: /^Closest leftover: Public post · sales-lead /,
+ });
+ expect(action).toHaveTextContent("Closest leftover: Public post · sales-lead");
+ expect(action).toHaveAccessibleName(/R \+0\.40/);
+ expect(action).toHaveAccessibleName(/Y 2\.40 · E 2\.00/);
+ expect(action).toHaveAccessibleName(/rank 1/);
+ expect(action).toHaveAccessibleName(/d 0\.12/);
+
+ const name = action.getAttribute("aria-label") ?? "";
+ expect(occurrences(name, "rank 1")).toBe(1);
+ expect(occurrences(name, "Y 2.40")).toBe(1);
+ expect(occurrences(name, "E 2.00")).toBe(1);
+ expect(occurrences(name, "R +0.40")).toBe(1);
+ expect(occurrences(name, "d 0.12")).toBe(1);
+
+ await userEvent.click(action);
+ expect(onSelectPost).toHaveBeenCalledWith(PAIR);
+ });
+
+ it("keeps residual guidance while announcing finite residual evidence once", () => {
+ const name = accessibleNameFor({
+ observed_response: null,
+ expected_response: null,
+ leftover_map_rank: null,
+ });
+
+ expect(name).toContain(
+ "Leftover residual R +0.40 after IRT main effects. Open this post to read sales-lead.",
+ );
+ expect(occurrences(name, "R +0.40")).toBe(1);
+ expect(occurrences(name, "d 0.12")).toBe(1);
+ });
+
+ it.each(ACTION_EVIDENCE_CASES)(
+ "announces %s action evidence once",
+ (_label, overrides, token) => {
+ const name = accessibleNameFor(overrides);
+ expect(occurrences(name, token)).toBe(1);
+ },
+ );
+
+ it("keeps every finite persisted pair-evidence badge in the same accessible name", () => {
+ render(
+ ,
+ );
+
+ const action = screen.getByRole("button", {
+ name: /^Closest leftover: Public post · sales-lead /,
+ });
+ expect(action).toHaveAccessibleName(/R \+0\.40/);
+ expect(action).toHaveAccessibleName(/Y 2\.40 · E 2\.00/);
+ expect(action).toHaveAccessibleName(/rank 1/);
+ expect(action).toHaveAccessibleName(/U \+0\.05/);
+ expect(action).toHaveAccessibleName(/U²\/R² 0\.02/);
+ expect(action).toHaveAccessibleName(/R̂²\/R² 0\.76/);
+ expect(action).toHaveAccessibleName(/2R̂U\/R² 0\.12/);
+ expect(action).toHaveAccessibleName(/R̂ \+0\.35/);
+ expect(action).toHaveAccessibleName(/ξ \(\+0\.50, \+0\.10\) ζ \(\+0\.50, −0\.02\)/);
+ expect(action).toHaveAccessibleName(/d 0\.12/);
+ });
+
+ it("keeps non-finite residual visual disclosure while omitting it and non-finite distance from the accessible name", () => {
+ render(
+ ,
+ );
+
+ const action = screen.getByRole("button", {
+ name: /^Closest leftover: Public post · sales-lead /,
+ });
+ expect(action).toHaveAccessibleName(/rank 1/);
+ expect(action).not.toHaveAccessibleName(/R —/);
+ expect(action).not.toHaveAccessibleName(/d NaN/);
+ expect(action).toHaveTextContent("R —");
+ expect(action).not.toHaveTextContent("d NaN");
+ });
+
+ it("falls back to the existing localized open action while preserving the visual non-finite residual marker", () => {
+ render(
+ ,
+ );
+
+ const action = screen.getByRole("button", {
+ name: /^Closest leftover: Public post · sales-lead /,
+ });
+ expect(action).toHaveTextContent(
+ "Open this post so the leftover criterion is current in Post quality.",
+ );
+ expect(action).not.toHaveAccessibleName(/R —/);
+ expect(action).not.toHaveAccessibleName(/d NaN/);
+ expect(action).toHaveTextContent("R —");
+ expect(action).not.toHaveTextContent("d NaN");
+ });
+});
diff --git a/frontend/src/components/LeftoverPairList.css b/frontend/src/components/LeftoverPairList.css
new file mode 100644
index 000000000..68ce129be
--- /dev/null
+++ b/frontend/src/components/LeftoverPairList.css
@@ -0,0 +1,20 @@
+.leftover-pair-action {
+ min-width: 0;
+ min-height: var(--size-touch-target);
+ flex-wrap: wrap;
+ align-items: flex-start;
+ gap: var(--space-control-gap);
+}
+
+.leftover-pair-action > .ticket-title {
+ min-width: 0;
+ flex: 1 1 18rem;
+ overflow-wrap: anywhere;
+}
+
+.leftover-pair-action > .post-badge {
+ min-width: 0;
+ max-width: 100%;
+ flex: 0 1 auto;
+ overflow-wrap: anywhere;
+}
diff --git a/frontend/src/components/LeftoverPairList.rankZeroAccessibleName.test.tsx b/frontend/src/components/LeftoverPairList.rankZeroAccessibleName.test.tsx
new file mode 100644
index 000000000..3f6e143fa
--- /dev/null
+++ b/frontend/src/components/LeftoverPairList.rankZeroAccessibleName.test.tsx
@@ -0,0 +1,41 @@
+import { render, screen } from "@testing-library/react";
+import { describe, expect, it, vi } from "vitest";
+import type { LeftoverPair } from "../api";
+import { LeftoverPairList } from "./LeftoverPairList";
+
+const RANK_ZERO_PAIR: LeftoverPair = {
+ pair_kind: "closest",
+ post_id: "post-rank-zero",
+ post_title: "Rank zero post",
+ criterion_code: "sales_lead_quality",
+ leftover_distance: 0.12,
+ leftover_residual: 0.4,
+ observed_response: null,
+ expected_response: null,
+ leftover_map_rank: 0,
+};
+
+function occurrences(value: string, token: string): number {
+ return value.split(token).length - 1;
+}
+
+describe("LeftoverPairList rank-zero accessible evidence", () => {
+ it("announces persisted rank 0 once when rank-zero guidance does not name the value", () => {
+ render(
+ "sales-lead"}
+ onSelectPost={vi.fn()}
+ />,
+ );
+
+ const action = screen.getByRole("button", {
+ name: /^Closest leftover: Rank zero post · sales-lead /,
+ });
+ const name = action.getAttribute("aria-label") ?? "";
+
+ expect(action).toHaveTextContent("rank 0");
+ expect(action).toHaveAccessibleName(/rank 0/);
+ expect(occurrences(name, "rank 0")).toBe(1);
+ });
+});
diff --git a/frontend/src/components/LeftoverPairList.stories.tsx b/frontend/src/components/LeftoverPairList.stories.tsx
index 916ab7e03..76727e77c 100644
--- a/frontend/src/components/LeftoverPairList.stories.tsx
+++ b/frontend/src/components/LeftoverPairList.stories.tsx
@@ -1,4 +1,5 @@
import type { Meta, StoryObj } from "@storybook/react-vite";
+import { expect, fn, userEvent, within } from "storybook/test";
import { LeftoverPairList } from "./LeftoverPairList";
const meta = {
@@ -69,7 +70,64 @@ export default meta;
type Story = StoryObj;
-export const ClosestAndFarthest: Story = {};
+export const ClosestAndFarthest: Story = {
+ args: {
+ onSelectPost: fn(),
+ },
+ play: async ({ canvasElement, args }) => {
+ const canvas = within(canvasElement);
+ const closest = canvas.getByRole("button", {
+ name: /^Closest leftover: Public post · sales-lead /,
+ });
+ const farthest = canvas.getByRole("button", {
+ name: /^Farthest leftover: Specification revision requested · negative /,
+ });
+
+ await expect(closest).toHaveAccessibleName(/R \+0\.40/);
+ await expect(closest).toHaveAccessibleName(/Y 2\.40 · E 2\.00/);
+ await expect(closest).toHaveAccessibleName(/d 0\.12/);
+ await expect(farthest).toHaveAccessibleName(/R −1\.10/);
+ await expect(farthest).toHaveAccessibleName(/d 2\.00/);
+
+ await userEvent.tab();
+ await expect(closest).toHaveFocus();
+ await userEvent.keyboard("{Enter}");
+ await expect(args.onSelectPost).toHaveBeenCalledTimes(1);
+ await expect(args.onSelectPost).toHaveBeenCalledWith(args.pairs[0]);
+
+ await userEvent.tab();
+ await expect(farthest).toHaveFocus();
+ },
+};
+
+export const NarrowDenseEvidence: Story = {
+ args: {
+ onSelectPost: fn(),
+ },
+ parameters: { viewport: { defaultViewport: "mobile1" } },
+ play: async ({ canvasElement, args }) => {
+ const canvas = within(canvasElement);
+ const closest = canvas.getByRole("button", {
+ name: /^Closest leftover: Public post · sales-lead /,
+ });
+ const farthest = canvas.getByRole("button", {
+ name: /^Farthest leftover: Specification revision requested · negative /,
+ });
+
+ await expect(closest.scrollWidth).toBeLessThanOrEqual(closest.clientWidth);
+ await expect(farthest.scrollWidth).toBeLessThanOrEqual(farthest.clientWidth);
+ await expect(closest.getBoundingClientRect().height).toBeGreaterThanOrEqual(44);
+ await expect(farthest.getBoundingClientRect().height).toBeGreaterThanOrEqual(44);
+
+ await userEvent.pointer({ target: farthest, keys: "[MouseLeft]" });
+ await expect(args.onSelectPost).toHaveBeenCalledTimes(1);
+ await expect(args.onSelectPost).toHaveBeenLastCalledWith(args.pairs[1]);
+
+ await userEvent.pointer({ target: closest, keys: "[TouchA]" });
+ await expect(args.onSelectPost).toHaveBeenCalledTimes(2);
+ await expect(args.onSelectPost).toHaveBeenLastCalledWith(args.pairs[0]);
+ },
+};
export const Empty: Story = {
args: {
diff --git a/frontend/src/components/LeftoverPairList.test.tsx b/frontend/src/components/LeftoverPairList.test.tsx
index 6972dd29b..949f5f9be 100644
--- a/frontend/src/components/LeftoverPairList.test.tsx
+++ b/frontend/src/components/LeftoverPairList.test.tsx
@@ -46,7 +46,7 @@ describe("LeftoverPairList", () => {
expect(screen.getByLabelText("Leftover pairs")).toBeInTheDocument();
const closest = screen.getByRole("button", {
- name: "Open leftover closest pair: Public post · sales-lead",
+ name: /^Closest leftover: Public post · sales-lead /,
});
expect(closest).toHaveTextContent("Closest leftover: Public post · sales-lead");
expect(closest).toHaveTextContent(
@@ -58,7 +58,7 @@ describe("LeftoverPairList", () => {
expect(closest).toHaveTextContent("d 0.12");
const farthest = screen.getByRole("button", {
- name: "Open leftover farthest pair: Specification revision requested · negative",
+ name: /^Farthest leftover: Specification revision requested · negative /,
});
expect(farthest).toHaveTextContent("R −1.10");
expect(farthest).toHaveTextContent("Y 0.90 · E 2.00");
@@ -148,7 +148,7 @@ describe("LeftoverPairList", () => {
);
const closest = screen.getByRole("button", {
- name: "Open leftover closest pair: Public post · sales-lead",
+ name: /^Closest leftover: Public post · sales-lead /,
});
expect(closest).toHaveTextContent(
"Leftover map places this post at ξ (+0.50, +0.10) and the criterion at ζ (+0.50, −0.02) after IRT main effects. Open this post to read sales-lead.",
@@ -383,4 +383,4 @@ describe("LeftoverPairList", () => {
);
expect(container).toBeEmptyDOMElement();
});
-});
+});
\ No newline at end of file
diff --git a/frontend/src/components/LeftoverPairList.tsx b/frontend/src/components/LeftoverPairList.tsx
index 6c8c549fa..1b7f1aea2 100644
--- a/frontend/src/components/LeftoverPairList.tsx
+++ b/frontend/src/components/LeftoverPairList.tsx
@@ -33,6 +33,8 @@ import {
formatLeftoverMapUnexplainedShare,
LEFTOVER_MAP_UNEXPLAINED_SHARE_ACTION,
} from "../leftoverMapUnexplainedShare";
+import { formatLeftoverMapDistance } from "../leftoverMapPlotLayout";
+import "./LeftoverPairList.css";
import { LeftoverMapPlot } from "./LeftoverMapPlot";
export type LeftoverPairListProps = {
@@ -43,6 +45,24 @@ export type LeftoverPairListProps = {
onSelectPost: (pair: LeftoverPair) => void;
};
+type AccessibleEvidenceKey =
+ | "residual"
+ | "observedExpected"
+ | "rank"
+ | "unexplained"
+ | "unexplainedShare"
+ | "explainedShare"
+ | "crossShare"
+ | "reconstruction"
+ | "coordinates";
+
+/** Join buyer-visible evidence without inventing unavailable values. */
+function leftoverPairAccessibleName(parts: Array): string {
+ return parts
+ .filter((part): part is string => typeof part === "string" && part.length > 0)
+ .join(" ");
+}
+
/**
* Closest and farthest leftover post–criterion pairs after IRT main effects.
*
@@ -115,7 +135,10 @@ export function LeftoverPairList({
const kindLabel =
pair.pair_kind === "farthest" ? t("Farthest leftover") : t("Closest leftover");
const criterion = criterionLabel(pair.criterion_code);
+ const visibleLabel = `${kindLabel}: ${pair.post_title} · ${criterion}`;
const residual = formatLeftoverResidual(pair.leftover_residual);
+ const residualBadge = Number.isFinite(pair.leftover_residual) ? `R ${residual}` : null;
+ const distanceBadge = formatLeftoverMapDistance(pair.leftover_distance);
const observedExpected = formatLeftoverObservedExpected(
pair.observed_response,
pair.expected_response,
@@ -160,6 +183,7 @@ export function LeftoverPairList({
pair.leftover_map_item_axis_1,
pair.leftover_map_item_axis_2,
);
+ const nextActionEvidence = new Set();
let nextAction: string;
if (coordinatesBadge !== null && personCoordinateValue !== null && itemCoordinateValue !== null) {
nextAction = tf(LEFTOVER_MAP_COORDINATES_ACTION, {
@@ -167,21 +191,25 @@ export function LeftoverPairList({
item: itemCoordinateValue,
criterion,
});
+ nextActionEvidence.add("coordinates");
} else if (explainedShareBadge !== null) {
nextAction = tf(LEFTOVER_MAP_EXPLAINED_SHARE_ACTION, {
value: explainedShareValue,
criterion,
});
+ nextActionEvidence.add("explainedShare");
} else if (unexplainedShareBadge !== null) {
nextAction = tf(LEFTOVER_MAP_UNEXPLAINED_SHARE_ACTION, {
value: unexplainedShareValue,
criterion,
});
+ nextActionEvidence.add("unexplainedShare");
} else if (crossShareBadge !== null) {
nextAction = tf(LEFTOVER_MAP_CROSS_SHARE_ACTION, {
value: crossShareValue,
criterion,
});
+ nextActionEvidence.add("crossShare");
} else if (reconstruction !== null) {
const signedReconstruction =
formatSignedLeftoverValue(pair.leftover_map_reconstruction ?? Number.NaN) ?? "—";
@@ -189,6 +217,7 @@ export function LeftoverPairList({
value: signedReconstruction,
criterion,
});
+ nextActionEvidence.add("reconstruction");
} else if (unexplained !== null) {
const signedUnexplained =
formatSignedLeftoverValue(pair.leftover_map_unexplained ?? Number.NaN) ?? "—";
@@ -196,6 +225,7 @@ export function LeftoverPairList({
value: signedUnexplained,
criterion,
});
+ nextActionEvidence.add("unexplained");
} else if (rankBadge !== null && observedExpected !== null) {
nextAction =
pair.leftover_map_rank === 0
@@ -214,6 +244,7 @@ export function LeftoverPairList({
expected: Number(pair.expected_response).toFixed(2),
},
);
+ nextActionEvidence.add("rank").add("observedExpected");
} else if (rankBadge !== null) {
nextAction =
pair.leftover_map_rank === 0
@@ -221,6 +252,9 @@ export function LeftoverPairList({
: tf(LEFTOVER_RANK_STRUCTURE_ACTION, {
rank: String(pair.leftover_map_rank),
});
+ if (pair.leftover_map_rank !== 0) {
+ nextActionEvidence.add("rank");
+ }
} else if (observedExpected !== null) {
nextAction = tf(
"Read observed Y {observed} and expected E {expected} after IRT main effects, then open this post.",
@@ -229,11 +263,15 @@ export function LeftoverPairList({
expected: Number(pair.expected_response).toFixed(2),
},
);
- } else {
+ nextActionEvidence.add("observedExpected");
+ } else if (residualBadge !== null) {
nextAction = tf(
"Leftover residual R {residual} after IRT main effects. Open this post to read {criterion}.",
{ residual, criterion },
);
+ nextActionEvidence.add("residual");
+ } else {
+ nextAction = t("Open this post so the leftover criterion is current in Post quality.");
}
return (