# Ask OKF service changelog

## 0.7.0 public observation — 25 September 2026

- Bind the service guide to the retained hosting and public SDK receipts:
  12 source-bound cases and 135 bounded HTTP requests. Keep the older 0.6.0
  receipt and separate public transport from client and legal acceptance.

## 0.7.0 — Evidence Connect source admission

- Pin the immutable Evidence Connect corpus and descriptor from DWP commit
  `7eeded763042ddd0070f4fed834c6074149e8e2f`, and a compatible v3 engine
  from Explorer commit `d6930bbcddaab616deec002d9e6efff6e3aae953`.
- Make Evidence Connect the default source while retaining all earlier source
  versions, frozen engine pairs and engine-specific replay identities.
- Make new questions on the review page use the assembler approved for the
  selected source version, including historical sources.
- Bind discovery and relationship assets to the manifest allow-list and shared
  per-request resource limits. Verify actual local source text and cursor
  rejection without making model calls.
- Update the landing page, tool version description and public verifier for
  six sources, three engines and ten permitted pairs. Deployment and connected
  client acceptance require separate observations.

## 0.6.1 — complete questions in connected clients

- Anchor the shared question pattern so both substring and whole-string regex
  matching accept the same non-blank text. The original `\S` matched a single
  non-whitespace character; a client applying a whole-string match rejected
  ordinary questions before contacting the service. A one-character control
  succeeded. The fix keeps types, lengths, budgets and evidence selection intact.
- Cover all three tools, Unicode, multiline questions, blank and overlong
  inputs, and equivalence with the original accepted set. Preserve all 0.6.0
  receipt bytes and validate their own historical build and runner.
- An installed connection must refresh its tool metadata after publication.
  A new session needs the plugin selected. See the
  [connection guide](../../docs/remote-mcp.md#connect-in-chatgpt) and the shared
  publication record below; code and local tests do not establish client access.

<!-- ask-okf-publication:start -->
## Recorded public deployment: 0.7.0

For the **latest recorded deployment and verification**, use the shared
[DWP service publication status](https://github.com/chris-page-gov/okf-dwp/blob/main/docs/service-publication.md). This dated observation is not a live health check.

On 25 September 2026, the [hosting record](https://github.com/chris-page-gov/okf-dwp/blob/0858f6318188f7812eaff78fce81bda7a5531f5b/validation/compact-delivery/v0.7.0/deployment.json)
records service **0.7.0** as deployed. The separate
[public SDK observation](https://github.com/chris-page-gov/okf-dwp/blob/0858f6318188f7812eaff78fce81bda7a5531f5b/validation/compact-delivery/v0.7.0/sdk/attempt-01/observation.json)
passed **12 evidence cases and 135 requests**,
reconstructing complete packages from bounded reads. It recorded
11,974,541 received bytes, no automatic retries and no model calls.

| Identity | Recorded value |
| --- | --- |
| DWP source | `7eeded763042ddd0070f4fed834c6074149e8e2f` |
| Context engine | `d6930bbcddaab616deec002d9e6efff6e3aae953` |
| Deployed runtime | `31d8c3436ed289bfd694b7889a9e5edea834ea8b` |
| SDK verifier | `31d8c3436ed289bfd694b7889a9e5edea834ea8b` |
| Local Worker SHA-256 | `9c7f31dc62e40b69de10a22aa7685becb16bbe22531d6ee78a9bbc357adfc680` |

The hosting record and public health report have different scopes: health does not
independently attest hosted Worker bytes. Delivery checks do not establish complete
legal evidence, specialist acceptance, answer quality or compatibility with a
particular ChatGPT, Data agent or Voice client. This observation includes no new
public browser journey. Earlier failures and observations retain their own scope.
<!-- ask-okf-publication:end -->

## 0.6.0 — partner and qualification preparation

- Pin final combined source `723bcc5b015ab38a026625c2148edbd784edf7c7` by
  exact manifest bytes. Retain 0.5.0's four sources and both archived engines;
  allow the new source only with the current c4f engine, giving nine pairs.
- Preserve historical packages and prior observations. Add ten actual local
  adapter/SDK cases, including the care-home question and an unknown-term
  control at 512 KiB. Four earlier complete-package hashes reproduce exactly.
- Add explicit current question/budget identities to the successor compact live
  verifier. It remains opt-in and bounded. The later public observation above
  does not establish model acceptance. Keep all 203 staff obligations open.

## Earlier engine-pinned replay preparation

- Retain exact c4f and b9 assembler modules with build-verified manifests and
  explicit compatibility for the four existing approved source revisions.
- Add engine identity to replay recipes, catalogue/read envelopes and health.
  Preserve historical v1 package bytes and the expected context-ID guard.
- Reconstruct old engine-unspecified links using at most two sequential bounded
  attempts. Compare complete package bytes; keep originating-engine uncertainty
  visible and fail closed for unavailable or ambiguous replay.
- Share file, transfer, decoded-work and deadline bounds across attempts. Keep
  read-only tools, inert source data, privacy and CSP boundaries.
- Clear stale evidence when a replay fragment changes in the same tab. Preserve
  engine/context/package identity through catalogue and evidence pagination.
- Retain separate local two-engine/four-source and Chrome observations. Earlier
  observations remain unchanged; package version and public deployment are not
  promoted by this candidate.

## 0.5.0 — household and statutory evidence candidate

- Pin the default combined corpus to
  `3ef0e786e9a18e76fa17c7d925ff509d6d6c9f84`: 901 semantic records,
  1,427 assertions and 20 selected statutory units. Keep machine extraction,
  legal applicability and specialist acceptance distinct; all 203 obligations
  remain open and the demonstrated household context remains insufficient.
- Preserve the preceding `9de52acf1db84b27f8933d80480eaa850e74fa33`
  staff corpus, earlier discovery corpus and original custody profile as three
  explicit historical versions. Add a separate verified staff manifest and
  version-routing, manifest-swap and package/lock/build identity controls.
- Verify all four versions using the official SDK 2 and SDK 1 clients against
  exact local immutable DWP Git blobs: 108 files hash-verified. Retain a new
  integration receipt and the earlier observations unchanged. Preserve the
  original custody context identity; each other receipt binds its actual engine
  and version rather than promising blanket cross-engine byte compatibility.
- Exercise compact replay for the current self-funded care-home question at
  256 KiB, prior-staff Child DLA/PIP, discovery-corpus abroad and historical
  custody. The current care-home package includes 35 records and 50 relationships.
  Keep the existing catalogue/reader schemas and primary receipt field names.
- Extend the remote verifier to seven full and four compact cases. Pace service
  HTTP requests by at least 750 ms, record counts and spacing, and disable
  automatic retries without changing production rate limits or dependencies.
- Link the landing page to the public beginner learning path. Retain all existing
  read-only tools, request/source bounds, portable builds, CSP and no-transform
  headers. Deployment, browser, ChatGPT and Voice checks remain separate gates.

## 0.4.0 — combined staff evidence candidate

- Make build output and receipts independent of real or symlinked locked
  dependency installations; bind the build script and test both layouts after
  relocation. Preserve the original local observation and rerun integration
  against the corrected build without weakening receipt checks.

- Prepare the combined DMG and ADM corpus as the default, including the proposed
  staff-task concepts, evidence requirements and explicit unresolved obligations.
  Pin the source to `9de52acf1db84b27f8933d80480eaa850e74fa33`; the release
  build rejects an unpinned candidate or altered manifest.
- Preserve the earlier `bf50ef8d91b9f1ccc2cbdb354198eae74c9ed752`
  full-source discovery corpus and `efb05c66616a9cd4328a86cf412780fe7bc7cf0b`
  custody profile as explicit versions with separate identities and integrity
  checks. Add manifest-swap, altered-byte and version-routing regressions, a
  real three-version loader test and a retained hash-bound local corpus replay
  receipt. Keep the architecture notes aligned with all three read-only tools.
- Extend the live verifier with a 256 KiB staff Child DLA/PIP context and compact
  replay across current, earlier corpus and original custody versions. Preserve
  the primary browser-receipt fields and existing historical observations.
- Send `Cache-Control: no-store, no-transform` on HTML only while preserving CSP.
  Other responses keep `no-store`. This follows the
  [documented Cloudflare JavaScript Detections behaviour](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/javascript-detections/#if-your-origin-sends-a-no-transform-header).
  Add route-level header regressions. Live transformation and cookie checks remain
  separate; no hosting issue is declared resolved by the candidate.
- Retain earlier release receipts. Source tests and local builds do not establish
  deployment, ChatGPT acceptance, Voice access or specialist approval.

## 0.3.1 — replay-link correction

- Remove a displayed replay link when the question or source version changes,
  or a new replay starts. A link created for an earlier context could otherwise
  reappear beneath a later context. Regenerate the link only when requested for
  the current verified context.
- Add a browser regression that recreates two different questions and checks
  the second link's question, version and context identity, plus repeated replay
  and version-change invalidation.
- Preserve 0.3.0 observations. Deployment and acceptance of 0.3.1 require their
  own build, hosted-service and browser receipts.

## 0.3.0 — compact evidence delivery

- Add bounded evidence catalogues, exact evidence reads and an inspectable
  browser replay page alongside the existing full-package tool. Context
  assembly and evidence authority remain separate from delivery and AI answers.
