Work log: 20 September 2026
Team handover · Backlog · Work packages · Changelog
Baseline and requested outcome
Start from merged DWP 5dab65d2ad21138c47e2ea364e5f74805b4e141f.
The owner requested all P0 items through BL010, then feasible P1 work in dependency
order, using the supplied staff questions. They subsequently requested a checked,
merged checkpoint for sharing with the team while implementation continues.
Tracking correction
The single aggregate status hid delivery work behind pending human review. BL005 and BL007 now explicitly name broader semantic modelling. Each backlog item has separate delivery/acceptance work packages, an executor, next action and evidence. The checker rejects aggregate completion with open work, completed work without evidence, and model execution labelled independent human acceptance. The detailed Markdown ledger is generated and checked against the register.
Ownership and handovers
| Workstream | Owned scope | Dependencies | Checkpoint state |
|---|---|---|---|
| Integration | Backlog, team handover, persona/journey matrix, model trials, contracts, CI, release and publication | Completed bounded work from the other streams | Tracking correction and team handover prepared for reviewed publication |
| Semantic profiles | Additive staff concepts/profile authoring and producer/evaluation | Frozen staff questions, source passages and generic context schema | Inspection complete; implementation in progress; no completion claim |
| Legal reconciliation | Official legal references, bounded tribunal discovery and auditable producer | Staff source candidates and official source observations | Discovery in progress; no applicability or specialist acceptance claim |
| Combined Reader | Additive ADM/DMG Reader, relationships, conceptual facets and browser evidence | Existing indexed contracts; semantic overlay when ready | Producer implementation in progress; no published combined Reader claim |
The existing pilot compiler scans knowledge/ recursively. Adding unrelated
authoring there would change frozen pilot hashes. New semantic/legal authoring
therefore uses additive domain-profile/ families with explicit contract updates
at integration, following the existing navigation precedent. Generated outputs
remain separate from frozen releases.
Checkpoint boundary
The first checkpoint publishes tracking, tests and the handover only. It does not publish unfinished agent outputs or claim the semantic expansion is complete. Subsequent increments must record their inputs, generated outputs, tests, actual consumer observations and remaining acceptance work before being marked complete. Existing local research and browser scratch files remain untouched; private correspondence stays outside Git.
Merged tracking checkpoint
PR 11 merged as
1d0c98f1475757b979efc62044bba36f68365e25. Both candidate checks passed, followed
by canonical main CI.
The independent review found no checkpoint defects. Private .email.md remained
ignored and untracked; browser and research scratch were excluded.
Additive implementation and independent review
- Integration produced all-occurrence persona/journey mappings, separate delivery and acceptance tracking, contract declarations and beginner documentation.
- Semantic modelling produced neutral concept aliases, source-grounded directed relationships, 40 task profiles and named unmet obligations. The supplied questions remain development cases; no model answer is produced by assembly.
- Legal discovery retained official identities and bounded decision metadata. A second-agent review caught unknown-instrument inheritance in the citation parser. The correction terminates inheritance and has explicit regression controls; it does not guess missing legal references.
- Combined Reader work preserved prior DMG identifiers and added ADM source records, search, facets, source/audit dates and relationships. Independent review caught a fallback assembly-index file overwritten by the final search shard. A byte-equivalence regression now checks the actual direct-context entry point.
- Review also required canonical validation of every emitted combined relationship, preserving authority, derivation, observation, evidence and rights.
- Small fixed-input trial export exposed a reusable consumer budget defect. Source records had been trimmed before final missing-evidence diagnostics were added, producing misleading empty fallbacks. The generic fix recomputes those diagnostics during trimming; the failed export remains separate evidence.
Substantive model judgements and representative-user acceptance remain separate from all these engineering checks. Source snapshots and earlier trial receipts have not been rewritten.
The first refreshed Explorer acceptance replay failed on its old implementation hash; replaying the non-DWP fixture changed only the implementation hash and observation times, preserving the package and context identifier. Broader CI then correctly rejected an older Heritage application receipt after the application bytes changed. Fresh browser execution passed all 100 questions at the declared threshold (mean 92.6) and all three local journeys, followed by 493 Python checks. No receipt was merely relabelled as evidence of a new execution.
A later review added controls against duplicate question identities, unknown cross-cutting personas and an unbound source-refresh receipts file. These defects were found using synthetic mutations; published source bytes remain unchanged.
Paired answer experiment
Both subscription clients received the same authored prompts and exact bounded packages for four staff questions and one unknown-term control. Twelve attempts are retained, including a rejected formatter event and a timeout. Ten structured responses contain 49 claims and 79 citations: eight pass mechanical checks; two fail exact quotations. Separate model critique identified household/date scope omissions and fragmentary citations. Independent engineering review verified the public projections contain final answers and usage, without internal thinking, session identifiers or account details. Specialist acceptance remains open.
Publication correction
GitHub push protection rejected the unpublished additive commit after classifying public legislation effect identifiers as possible API keys. An unchanged diagnostic retry was rejected by automatic approval review. No bypass was attempted. Bounded, unauthenticated official XML reads verified all 179 identifiers as effect metadata. The public projection omits unused opaque identifiers while retaining useful metadata, source locators and digests. Current provenance is regenerated; fresh browser receipts bind that projection. Historical trial packages and receipts remain immutable, with their original source input explicitly archived.
The final local Python suite passed 245 tests. Explorer CI encountered one 20-second browser rerender-test timeout; the unchanged rerun passed that test. Earlier failed runs remain available. Canonical post-merge CI and the actual published browser journey are separate release checks.
A recursive comparison of the regenerated and historical trial indexes found exactly 216 changed leaves: 215 provenance hashes and the bundle snapshot. Concepts, relationships, identifiers, source text, routes, requirements and ordering are unchanged. The historical answers remain attached to the historical bytes; they are not represented as fresh calls against the new snapshot.
A final alias control found that ordinary “is”/“Is” does not resolve as Income Support: the existing acronym alias is case-sensitive. The broader full-name alias still belongs to the preserved custody concept. Neutral Income Support modelling is named explicitly in BL005's remaining agent work, rather than silently broadening the legacy concept's scope.
Merged additive release
DWP PR 12 merged as
5ba28e976aca3c93633494e0b373e2a3b6aae49f, after both candidate validations
passed. Its immutable content commit is 9de52acf1db84b27f8933d80480eaa850e74fa33.
Explorer PR 126 merged
as efde81d3ff1f016c8e3953336333f2c5967b80cf after the full required suite passed.
Post-merge DWP validation and Explorer Pages publication run separately.
Service 0.4.0 has 43 passing tests and exact three-version integration against 68 hash-verified local files. Explorer PR 127 retains earlier replay identities and adds the new staff corpus. A changelog-only integration conflict was resolved by keeping both entries; runtime bytes did not change. Hosting and public browser acceptance remain separate release steps.
Portable deployment build
The service CI correctly rejected a receipt made with an externally linked
node_modules directory: esbuild had treated dependency real paths as project
source paths, changing the bundle and input list. A locked normal installation
reproduced CI. The build now preserves dependency symlink paths, and a regression
compares linked and real installations at different locations. Worker, Node and
build-receipt bytes match. The 23 source inputs exclude external dependency paths.
Original local observations remain under the service's validation history; they
were not relabelled as portable or deployed evidence.
Public combined Reader acceptance
DWP canonical validation 35533814909 passed. Explorer Pages deployment 35533781355 passed. Three actual public browser engines verified all 21 application files and 249 fetched corpus files each. The separate five-facet journey verified 235 corpus files; the union is 261. All named functional, keyboard and targeted accessibility checks passed, with no console errors. The initial five-second wait failure is preserved; bounded sixty-second reruns passed with phase timings. BL024 is complete for this declared publication scope. BL019's human assistive-technology and representative-user acceptance remains open.
Service publication
Explorer PR 127 merged as fc71d65b8f5cfc860d52afe98a5e45b88231f3e5 after all
required checks passed. The existing public Site deployed service 0.4.0 as hosting
version 8. The actual SDK run passed five question/version cases and exact compact
reconstruction for all three approved source versions. The new staff package has
50 records, 36 relationships and 216,464 bytes; it remains insufficient.
Independent browser-verifier review found three false-pass risks: catalogue metadata compared with itself, loose CSP matching and credential-bearing replay URLs. The verifier now compares with the independently hash-verified full package, requires the exact restricted policy and rejects URL credentials before launching a browser. At that stage, thirteen offline controls and independent re-review passed; the later native-response amendment increased the suite to fifteen. Actual public browser observations are retained separately from this code review.
Explorer's canonical Pages run 35534787876 passed after the service merge.
The normal Explorer checkout has been fast-forwarded to the merged main branch;
untracked research is preserved. DWP's private-input checker still confirms
that root and nested .email.md paths are ignored and none is indexed.
Actual compact-reader observation
The first staff run retained a Chrome driver-decoding byte-count failure, Firefox functional pass with hosting-cookie console failures, and a WebKit clean pass. Independent review confirmed the driver discrepancy; the amended observer reads only cloned browser-native responses and leaves the original fetch promise and response unchanged. Fifteen offline controls and re-review passed. The second run passed all three functional journeys, with 24 calls each and no rate-limit failures. Chrome and WebKit passed strict console checks. Firefox retained invalid-domain hosting-cookie warnings; BL023 remains open. Both harness versions and every failed observation are retained. The passing journey checks every catalogue field against the hash-verified full package, not against itself.
The exact historical compact-reader suite also completed all twelve functional journeys, including changing question A to B, stale-response handling, replay recreation and invalid-fragment/markup controls. Chrome and WebKit passed all eight strict gates; Firefox's four strict gates failed only on hosting-cookie warnings. Some historical cases intentionally use synthetic delayed or hostile responses; those are UI safety controls, not untouched live-source observations. Raw traces remain outside the public repository; safe summaries identify scope.
Final integration review also required two preservation controls: public combined Reader checks now reject existing output directories before browser launch, and CI checks the saved service artefact census, byte digests and outcome bindings offline. The initial failed runs stay failures. The later harness guard has offline regression tests; it is not described as a fresh browser execution.