Temporary planning review record. The report below is reproduced verbatim as returned by the independent read-only reviewer (Plan agent, Opus model, launched 3 October 2026 about 14:35 BST). Only this front matter and note were added. Line numbers refer to the package as it stood when the reviewer read it. Resolutions are in the round-2 resolution matrix.
I've finished the review. My report follows; nothing was edited.
Review PH: how the plan covers the past year's planning work¶
1. Verdict¶
The plan engages thoroughly with the 2–3 October research, the owner ledger, the v10 pack, the QM v2 tracker, FEAT-011/012, eligibility D1–D7, #3335 and the notification stack. Its coverage of the rest of the past year is uneven, and it contradicts several approved or owner-decided designs without recording a supersession.
Inventory §10 marks five earlier documents as "background" or "read before F1/F3". That defers the reading; it does not dispose of them. Two of them contain constraints the plan breaks today.
The five changes that matter most:
- Remove the per-project commit sequence from the canonical transaction (E25). Adopt Chris's ADR-019 write gate in its place. FEAT-024 measured that one shared per-project document in every save makes up to 40% of saves exhaust their retries at 10 reviewers, and ADR-019 exists to remove exactly that.
- Resolve the conflict between the deletion design and amendment J. The reversible-deletion ADR-014 (product decisions approved 12 August; its flag is on
main) physically deletes a search's Studies after 24 hours. Amendment J and QD1 forbid that. The plan says "no feature doc found". - Define whether an autosaved draft holds a review slot. Every earlier capacity design ties the slot to the first explicit Save. The plan's drafts contract is silent, so the capacity rule and today's reviewer copy both become wrong.
- Map everything that already exists into the new model. That means eligibility D8 (five decisions, 24 September), the generated truth table, and the per-stage settings already on
main: target enforcement, the in-progress limit, hiding excluded studies, their progress grouping, and the search and partition filters. - Build on the approved question-extensibility and validation specifications instead of rewriting them. That covers response modes, metadata, preserved answers under a changed parent, the per-answer definition version, and FEAT-020's shared rules file and fixtures. Three items are missing from scope entirely: annotation import from other tools (FEAT-004), routing studies by answer values (FEAT-008 phase 3), and making search import robust enough for P1/P2.
2. Coverage table¶
Status is the document's front-matter status. "Justified?" judges how the plan treats the document.
| Document or decision set | Status | Plan's treatment | Justified? | Gap and recommendation |
|---|---|---|---|---|
| FEAT-001 annotation versioning README (D1–D57) | In-Review, Feb | Partly. D38 adopted as a proposal; pendingAnswer, migration step 6 and "gold = latest version" listed as superseded; D51/D53–D55 parked as E34 | Partly | D28, D49, D50-revised and D57 are contradicted with no record (PH-16). Breaking-change transitivity and the stored resolved question set are dropped (PH-18). D54/D55 are product rules, not engineering (PH-17). README rollback by $unset (line 579) not listed |
| FEAT-001 design session (D37–D57) | Approved, Feb | Not cited directly | No | Same as the row above |
| FEAT-006 reconciliation design decisions D1–D50 and README | Draft / In-Review, Feb | D10, D13/D14, D18 and D30 recorded as superseded | Partly | §8 production check (zero reconciled records) ignored (PH-08). D12, D15, D19–D28, D33 and D35 superseded silently (PH-26) |
| FEAT-003 question management, admin decision framework | In-Review, Feb | Crosswalk says QM-13 "retained and extended" | No | Per-session reconstruction categories and the 4-step decision flow are absent from C4, E1 and U6 (PH-18) |
| FEAT-007 screening profiles | In-Review | Listed as conflicting | Partly | Just-in-time admin adoption and the success metrics are dropped (PH-23). "Immutable once used" is superseded by Q-26 without a record |
| FEAT-008 stage filtering | In-Review | "Amend in R3a" (pass-forward only) | No | Filter-set model, routing by answer values and the select-next budget are not dispositioned (PH-05) |
| FEAT-009 screening annotations | In-Review | Conflicts recorded | Partly | Reconciliation pool settings, bypass criteria and reason truncation are not mapped (PH-24) |
| FEAT-010 stage settings | In-Review | "Stages unordered" superseded | Partly | Six existing policy settings and two filters have no home under shared forms (PH-05) |
| FEAT-011 PRISMA | Approved | Amendments A–L | Yes | Except amendment J against ADR-014 (PH-02) |
| FEAT-012 dedup service spec | Approved, Mar | Amendment L adopts it | Yes | Import-time matching runs inside a 5-minute import job (PH-09) |
| FEAT-013 export and data-export-analysis | Draft | "Input to C11 and the completed-sessions-only fix" | Partly | No check that blinded exports hide identities; #3335 D11 download ownership missing (PH-25) |
| FEAT-014 project templates | Draft | Listed | Partly | System templates break domain principle 5 (PH-27). Templates could build the new seed projects |
| FEAT-017, FEAT-020, FEAT-027 (#2629) validation | Draft / Approved / PR | Inventory row only; harvest #2986 | No | E23 re-specifies what FEAT-020 already defines (PH-07) |
| FEAT-004 annotation import | Draft (marked "urgent R1") | Not mentioned; confused with question import | No | PH-10 |
| Question-extensibility architecture and ADR-011 | Approved, Sep | Inventory row only | No | PH-06 |
| QM v2 context (tracker, implementation history, decisions) | Approved, Apr | 101-requirement crosswalk | Mostly | The "complete but not wired" lesson is missed (PH-11). D010, ADR-010 renames, ADR-011 two-level drafts and training rounds not used (PH-33) |
| Eligibility policy D1–D8 and truth table | In-Review; D-decisions by Chris | Q-24 maps D1–D7 | No | D8 omitted; the generated truth table is not reused (PH-04) |
| Grouped review configuration (#3732, merged) | Code | Target override made legacy-only | Partly | Four other fields unplaced (PH-05) |
| #3335 authorization plan (D1–D12) and authority-transition plan | Handover / Approved | WP1d, WP9, WP11, G-D and D10 integrated | Mostly | D11 export downloads (PH-25). New background jobs not classified under M5/P9 (PH-15) |
| Reviewer tracking overhaul, session-model redesign, capacity handover, copy review, ADR-008 | Approved / Draft | "Background; read before F1/F3"; the redesign is not mentioned | No | Draft vs slot semantics (PH-03); copy (PH-19); ADR-008 conventions (PH-30) |
Reversible-deletion ADR-014 (uncommitted), its audit and the main flag |
In-Review; product decisions approved 12 Aug | "No feature doc found" | No | PH-02 |
| Staged search import (#2612) and the May incident | Open PR / incident | Not mentioned | No | PH-09 |
| FEAT-024, ADR-019 and the write-contention note | Approved / In-Review / Proposed | C7/C8 amendments | Partly | PH-01 |
| Feature-flag overhaul and flag administration | In-Review | Not mentioned | No | PH-14 |
| AF2 programme plans and approved validation presentation plan | In-Review / Approved | Extension points; X-AF2-PR9 | Partly | pdf-tools dependency (PH-20). Approved status vocabulary not used (PH-19). FEAT-002 README per-question autosave not superseded (PH-21). Perf gate not reused (PH-32) |
| Stage-review v4 handoff | Spec, 21 Sep | Retained; owned by AF2 | Yes | One-key Include/Exclude and auto-advance against derived decisions (PH-35) |
| v10 pack and the 28 September classification handover | Historical | 44-entry crosswalk | Mostly | The handover's "superseded approaches to avoid" list is not carried as UX constraints (PH-33) |
| #2621 prototypes; redesign v7 | Draft | Inventoried | Yes | — |
| Study Management (FEAT-018) | In-Review | "Library stays" | Partly | New PRISMA and dedup surfaces have no placement (PH-31) |
| Bulk PDF (FEAT-021, ADR-012/015/017) | In-Review | P1 retrieval join | Yes (high level) | — |
| Material 3 (FEAT-023) | In-Review | UI standard | Yes | — |
| FEAT-025 allocation and keyword highlighting; FEAT-026 batches | In-Review | AL1, X-BATCH | Mostly | Where keyword lists live after profiles (PH-28) |
| Project membership status | In-Review | Not mentioned | No | PH-22 |
| Product roadmap, roadmap migrations, user-guide drafts | Draft | Not mentioned | No | PH-21 |
| Funding documents (NC3Rs, SSI RSMF) | Approved | Not mentioned | No | PH-12 |
| Browser-compatibility analysis and UI audits | Draft, May | Not mentioned | No | PH-13 |
| ADR-009 domain vs application services | Approved | Not mentioned | No | PH-30 |
| Features open-questions register | Approved | Not mentioned | Mostly covered implicitly | Custom PRISMA source types (FEAT-011 open question) unaddressed |
3. Findings¶
Paths: PLAN = /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/; MAIN = /home/chris/workspace/syrf/main/; HO = /home/chris/workspace/syrf/handover/.
| ID | Sev. | Location | Finding | Evidence | Recommended change |
|---|---|---|---|---|---|
| PH-01 | Major | PLAN contracts.md:444-446; domain-model.md:143, 174; open-questions:127 (E25); acceptance-criteria.md:90, 172 | Every canonical Save/Complete increments one per-project counter inside its transaction. FEAT-024 proved that per-project documents in the source transaction cause the contention: 0 conflicts without them, 428 with them, at 10 reviewers on different Studies; 399 of 1,000 saves exhausted retries. ADR-019 moved that work off the save path, and Chris set its write gate (b): under 10% p95 or at most +2 ms, and zero save failures at ½/5/10 reviewers, same-Study and different-Study. AC-R2a-19 allows 20% slower, AC-M0-02 tests only 3 reviewers, and neither tests contention. This reopens review B-31's fix with new evidence. | HO/FEAT-024-design-note-write-contention-2026-09-15.md:56-71; MAIN/docs/decisions/ADR-019-materialized-statistics-async-point-fold.md:24-30, 40-49, 68 | Drop the in-transaction counter. Order history either from commit cluster time recorded by an asynchronous indexer (the ADR-019 fold pattern) or from per-Study versions plus a watermark. Put ADR-019 gate (b) into AC-M0-02 and AC-R2a-19 using FEAT-024's PS-WRITE harness. Add a storage-ADR rule: no per-project document in the source transaction. |
| PH-02 | Major | PLAN source-status-inventory.md:254; prisma-amendments.md:165-176 (J); domain-model.md:37-39; integrated-plan.md:747 | ADR-014 (uncommitted worktree) records product decisions approved on 12 August: project and search deletion get a 24-hour grace period, then Project, Search and Study documents are physically deleted, leaving minimal tombstones with no content. The deletionLifecycle flag on main is that design's flag. Amendment J (approved 3 October) and QD1 forbid erasing identification history or published evidence. The new canonical collections are not in ADR-014's deletion scope, so they would be orphaned or need a cascade. The plan says "No feature doc found", so review B-16's fix is inadequate. |
/home/chris/workspace/syrf/.worktrees/bulk-pdf-deletion-lifecycle/docs/decisions/ADR-014-reversible-deletion-and-permanent-tombstones.md:14-17, 59-74, 142-146, 220-250, 285-295; HO/AUDIT-deletion-lifecycle-worktree-2026-08-17.md:1-27; MAIN/src/charts/syrf-common/env-mapping.yaml:786-794 | Inventory ADR-014. Record the conflict in register §2. Re-frame Q-33 as "which governs for admitted projects" (§5 Q1). Make X-DEL require ADR-014's manifest and tombstone model to cover the canonical collections, or exempt identification history from physical removal. |
| PH-03 | Major | PLAN contracts.md:250-256 (drafts), 323-330 (C7); open-questions:123 (E21); source-status-inventory.md:410-413 | Earlier designs all say an explicit Save secures the slot: the session-model redesign (a slot is held by either a reservation or a session, never both), the capacity handover, the copy review ("saving secures your spot"), the integration proposal ("idempotent graduation/release") and the research ("reserved is transient; draft can persist"). The plan never says whether a draft-only session holds a slot, or what happens when a reservation lapses while the server keeps the draft. Today's copy ("unsaved answers will be lost") becomes false. | MAIN/docs/features/review-session-model-redesign.md:180-187, 211-224; MAIN/docs/planning/session-capacity-suspended-sessions-handover.md:107-110, 126-129; MAIN/docs/planning/session-copy-review.md:84-97, 188, 311-323; pr3617 review-statistics-allocation-batching-integration-2026-10-03.md:68; screening-specialised-annotation-research.md:536, 617 | Add the graduation rule to E18/E21 and C7: first explicit Save secures the slot; a draft never holds capacity. Define what a reviewer sees when they return with a draft to a full study. Add acceptance criteria. Revise the copy in C17 (§5 Q2). |
| PH-04 | Major | PLAN open-questions:65 (Q-24), 198 (A-16); contracts.md:290 | Eligibility D8 (Chris, 24 September) has five decisions and none is mapped. (1) Removing own work is allowed "until annotation versioning replaces deletion". (2) Leftover claims are released. (3) A disabled stage cannot be opened, which collides with a shared session reachable from another stage. (4) Hiding excluded saved work, which collides with EW1. (5) An admin may reconcile before readiness, with a warning. The generated truth table and its Mongo-seeded row tests are not reused for AC-R3a-02. This extends review A-08, whose fix is incomplete. | MAIN/docs/planning/review-eligibility-policy.md:1087; MAIN/docs/planning/review-eligibility-truth-table.md:15-17 | Add a D8 row to Q-24/A-16 with a mapping for each sub-decision (§5 Q3). Extend the existing truth table with step and route columns instead of a new C6 table. |
| PH-05 | Major | PLAN contracts.md:288 (C6), 323-330; open-questions:67 (Q-28); domain-model.md:93; source-status-inventory.md:367 | Settings that exist on main have no home in the new model and no shared-form rule: target enforcement, the in-progress limit, hiding excluded studies, excluded-study progress grouping, self-reconciliation, and the stage's search and partition filters. The pool-entry event records "filter versions" that C6 never defines. FEAT-008's filter-set model and its routing by answer values (phase 3; planned since November 2025) are undispositioned. Issue #3876 would make reviewer tracking a per-stage setting too. This extends review A-10 (Q-28). |
MAIN/src/libs/project-management/SyRF.ProjectManagement.Core/Model/ProjectAggregate/StageEntity/ReviewConfiguration/StageReviewConfigurationRecord.cs:86-95; …/StageEntity/Stage.cs:302, 332-335, 357-358; MAIN/docs/features/stage-settings/README.md:158-170, 183-194; MAIN/docs/features/stage-filtering/README.md:66-73; gh issue #3876 | Add a placement table to C6/C4: form-owned vs stage-owned, plus the rule when stages bound to one form differ. Define the filter element of a stage settings version. Disposition routing by answer values (§5 Q8). Add #3876 to Q-28. |
| PH-06 | Major | PLAN contracts.md:196-203; domain-model.md:75; source-status-inventory.md:237 | The approved extensibility architecture defines: a response is a value or a response mode; validated metadata; a required _reason; descendants suppressed by a parent change are preserved, not deleted, and the backend "must not tree-shake" them; exports must resolve suppression; every response is stamped with a definition version; and an explicitly undecided question, whether definitions are frozen once used or snapshotted per response. None of this is in C4, C1, C2, E23 or C11. The plan answers the open question implicitly. |
MAIN/docs/features/question-management/annotation-question-extensibility-architecture.md:87-93, 169-191, 941-945 | Add response modes and metadata to C4 version content and the C1 payload. Make canonical Save keep suppressed answers. Add a suppression rule to C11 exports. Map the definition-version stamp to version references. Record that the open question is settled by frozen versions. Use response modes for UA1/AG3 N/A handling. |
| PH-07 | Major | PLAN open-questions:125 (E23); integrated-plan.md:399-401 | E23 specifies one applicability rule set with shared .NET and AF2 fixtures from scratch. FEAT-020 (approved) already has a formal specification, a single-source rules file used by back end, front end and fixtures, a JSON-schema code-generation strategy, and test fixtures; a validator on main reads the file. FEAT-017 plans log-only, then soft, then strict rollout to manage front-end/back-end divergence (rated HIGH). FEAT-027 (#2629) proposes loading rules once at start-up. None is cited. |
MAIN/docs/features/annotation-questions/formal-specification.md:606-684; …/annotation-question-rules.yaml:1-9; MAIN/src/libs/project-management/SyRF.ProjectManagement.Core/Validation/AnnotationQuestionPlacementValidator.cs; MAIN/docs/features/backend-annotation-validation.md:147-170, 242-264, 913-951; gh pr view 2629 |
Base E23 on FEAT-020's rules and fixtures; choose code generation or load-once at F1. Run the validator log-only on legacy saves from R0/R1 to measure divergence before R2a's strict Complete, and use the log as evidence for E10's "legacy-completed, unvalidated" decision. |
| PH-08 | Minor | PLAN open-questions:80 (Q-35); acceptance-criteria.md:277, 442; migration-adoption-rollback.md:102 | In February, production held 194,741 sessions and 3,096,894 annotations with zero reconciliation flags, and today's reconcile route has no navigation link. The plan still builds legacy-authority handling, a seed project and acceptance criteria for legacy reconciled answers. Whether production is still near zero is UNVERIFIED. This questions review B-23's fix on efficiency grounds. | MAIN/docs/features/reconciliation/design-decisions.md:591-600, 982; PLAN source-status-inventory.md:88-93 | Ask for an aggregate-only count before F4. If it is near zero, keep only a fail-closed refusal and drop the Q-35 machinery. |
| PH-09 | Major | PLAN integrated-plan.md:689-690; acceptance-criteria.md:353 | P1 adds Citation capture and P2 adds identifier matching inside search import. The import job still has a 5-minute timeout. The May incident showed imports above about 3,000 studies fault (one 5,704-study CSV took more than 9 minutes), plus duplicate-event saga crashes. Open PR #2612 (staged import with a batch identifier and hidden pending studies) overlaps P2's pending-dedup status. None of this is mentioned. | MAIN/src/services/project-management/SyRF.ProjectManagement.Endpoint/Consumers/ReferenceFileParseJobConsumer.cs:88; HO/incident-2026-05-28-bulk-update-deadlock.md:18-21, 114-120, 222-244; gh pr view 2612 |
Add an X-IMPORT prerequisite for P1: #2612 or an equivalent, a sized timeout with heartbeat and stall watchdog, and idempotent saga creation. Align pending-dedup with staged-pending status. Add acceptance criteria for 5,000- and 50,000-record imports. |
| PH-10 | Major | PLAN migration-adoption-rollback.md:39 | FEAT-004 (import answers from Rayyan, Covidence or spreadsheets; marked "urgent" for adoption) has no disposition. The writer list mislabels question-template import (#2781/#3934) as "annotation import". Imported answers need a provenance kind, counting rules, independence labelling and PRISMA treatment. | MAIN/docs/features/annotation-import/brief.md:22-26; gh pr view 2781, gh pr view 3934 |
Decide at G0 (§5 Q6). Correct the inventory label. Add an "imported external assessment" kind to C1/C3. |
| PH-11 | Major | PLAN integrated-plan.md:958-959 | QM v2 completed M001–M004 but never wired the UI to the API, leaving a dormant 738-file stack. The plan's main parallelisation rule (build against fakes, integrate at the ship gate) repeats that pattern with no mitigation. | MAIN/docs/planning/qm-v2-context/README.md:29; …/qm-v2-implementation-history.md:348-367 | Add a walking-skeleton rule: each release's first PR is a thin end-to-end path behind its flag; cap how long a lane can build against fakes only; add a risk row. |
| PH-12 | Major | PLAN integrated-plan.md:578-616; open-questions:71 (Q-30); acceptance-criteria.md:56 | NC3Rs has unpaid outstanding deliverables: question-editing interface, screening types and study filtering, in-app qualitative reconciliation, enhanced custom groups, bulk PDF upload. The SSI RSMF EoI commits to versioning in months 4–8 of a project starting from 1 October 2026, WCAG 2.1 AA with an independent audit, a public roadmap, and the claim that "blinding of reviewer identities and random study serving are core platform behaviours, not optional settings". Q-30 treats blinding as a stage setting with a default. Whether the funding is current is UNVERIFIED. | MAIN/docs/funding/nc3rs.md:166-176; MAIN/docs/funding/ssi-rsmf.md:53-58, 62-83, 100 | Add a funder-deliverable traceability table. Set AC-ALL-07 to WCAG 2.1 (or 2.2) AA with an audit step. Ask §5 Q4 and Q5. |
| PH-13 | Major | PLAN ui-coverage-comparison.md:70; acceptance-criteria.md:79 | The plan keeps the new question editor as the base, but it uses native HTML5 drag events. The May compatibility analysis found that dead on iPad touch and broken on Firefox, and wrongly assumed QM v2 would replace it. There is no browserslist and the build targets ES2022. The UI standard has no browser or device matrix. | MAIN/docs/planning/non-chromium-browser-compatibility-analysis.md:27-37, 59, 62; MAIN/src/services/web/src/app/project/project-admin/question-management/design/annotation-question-tree-drag-drop.feature.ts:509-527; MAIN/src/services/web/tsconfig.json:42 | Add a browser and device matrix to UI-6 or AC-ALL. Require CDK drag-and-drop for R1a. Make the analysis's BUILD.F1–F3 fixes an R1a precondition. |
| PH-14 | Minor | PLAN integrated-plan.md:289-291; open-questions:52 (Q-25), 204 (A-22) | The flag overhaul plans per-project targeting (P7) and says domain enrollment must stay separate from flags. R0's admission service and Q-25's AF2 per-project route ignore it, so two per-project mechanisms could be built. This extends review C-05's fix. | MAIN/docs/planning/feature-flag-overhaul/README.md:229, 239-242, 313 | Define R0 admission as that domain enrollment. Route AF2 production pilots through P7 targeting keyed to admission. Get the flag programme owner's sign-off at F1. |
| PH-15 | Minor | PLAN contracts.md:550-566 (C16); open-questions:132 (E30) | The authority transition (approved) classifies every background job family and quarantines jobs it cannot admit. New consumers also need broker permission rules. The plan adds new job families (publication phase 2, adoption backfills, retroactive dedup, expiry, lifecycle transitions, outcome recomputation) without classifying them. | MAIN/docs/planning/application-authority-transition/queued-work-ledger.md:12-16, 141, 146 | Add an M5/P9 classification and the broker rules to C16 and each release ADR. |
| PH-16 | Minor | PLAN open-questions:122 (E20), 129 (E27); contracts.md:138-142; domain-model.md:43-45, 217 | Approved FEAT-001 decisions contradicted without a record: D49 (no entity-instance concept) against E27's "entity instances"; D50-revised (no Study back-references, to avoid contention) against E20's Study projection and version bump; D57 (versions identified as parent ID plus number) against revision GUIDs; D28 (one global question collection with scope) against principle 5. C2's entity path does not separate option-keyed multi-select branches from reviewer-created entities. | MAIN/docs/features/annotation-versioning/design-session.md:358-359, 366, 368, 375; …/README.md:614; MAIN/docs/superpowers/specs/2026-08-07-annotation-answer-branch-clarity-design.md:16-19 | Add rows to register §2 with rationale. Define the entity-path element kinds in C2. |
| PH-17 | Minor | PLAN open-questions:136 (E34) | D54 (a reconciler must acknowledge stale answers before submitting) and D55 (per-project enforcement levels: flag, block or inform) are product rules. D54 conflicts with RE2's Complete-anyway model. | MAIN/docs/features/annotation-versioning/README.md:548-556 | Move to a Chris question (§5 Q10). |
| PH-18 | Minor | PLAN contracts.md:198; open-questions:103 (E1), 152 (U6) | Dropped mechanics: a change is breaking if any skipped version was breaking; a stored resolved-question set per session version (which can feed PS1 usage); FEAT-003's per-session categories, including questions newly applicable after an ancestor change and per-session breaks hidden behind a non-breaking flag; the 4-step admin flow (scope, non-breaking, breaking, confirmation). | MAIN/docs/features/annotation-versioning/README.md:360-368, 372-387; MAIN/docs/features/question-management/README.md:232-298 | Use these as the impact-manifest categories in E1/E22 and the structure of the U6 dialog. |
| PH-19 | Minor | PLAN contracts.md:591-593; integrated-plan.md:1023-1026 | The copy contract ignores vocabulary that is already approved and shipped: the AF2 validation plan (approved 14 September, merged #3467) with four separate facts and four states, "Ready" for answers vs "Completed" for the review, and the "Save progress" button; "review slot" from the copy review; and QM v2 ADR-010's warning about five conflated "draft" concepts. The plan uses "draft" for five different things. | HO/2026-09-13-af2-validation-presentation-plan.md:3, 35-62; MAIN/src/services/web/src/app/shared/annotation/annotation-form-v2/annotation-form-v2.component.html:466; MAIN/.local/qm-designer-handover/02-domain-and-language/ADR-010-qm-v2-ubiquitous-language-renames.md:19-28 | Extend the approved four-state model with Needs updating and Outdated. Keep "Save progress". Give each kind of draft a distinct term. |
| PH-20 | Major | PLAN integrated-plan.md:641-646, 693, 748 | AF2 still needs the v1 pdf-tools subsystem to mark, move and delete graph regions and to show cropped images; that migration is unscheduled and also blocks Phase 4 PR 9's cleanup. Canonical extraction (O1) runs on AF2 only, and R4c depends on it. X-AF2-PR9 covers neither. | MAIN/src/services/web/CLAUDE.md:361 | Add an X-PDFTOOLS join to O1 and R4c, or accept the gap explicitly in O1's scope. |
| PH-21 | Minor | PLAN decision-register.md:199-232; source-status-inventory.md:348-371 | Published documents still describe superseded behaviour and are not in the supersession lists: the roadmap (three releases, 16 phases; "staging shares the same DB"), the release-⅔ migration drafts (auto-promotion, $unset, platform-wide backfill), the user-guide drafts (random-only assignment, "Annotator A/B"), and the FEAT-002 README (per-question pendingAnswer autosave). |
MAIN/docs/roadmap/product-features-roadmap.md:47-63, 295-304; MAIN/docs/roadmap/migrations/release-2-migration.md:29, 40; …/release-3-export-prisma.md:29; MAIN/docs/user-guide-drafts/FEAT-006-reconciliation-workflow.md:31-36; MAIN/docs/features/annotation-form-v2/README.md:59, 193-204 | Add them to the lists. Replace the roadmap at G0. |
| PH-22 | Minor | PLAN contracts.md:248 | A "qualifying contribution" must be "eligible", which is undefined. Disabled members lose access to review work, but whether their completed sessions still count and still take part in reconciliation is unstated. | MAIN/docs/features/project-membership-status/README.md:22-27 | Define it (§5 Q7). |
| PH-23 | Minor | PLAN migration-adoption-rollback.md:72-76; integrated-plan.md:704-710 | FEAT-007's admin-initiated just-in-time screening adoption and its metrics (80% fewer multi-project workarounds; under 5 minutes to set up title/abstract → full text; select-next p95 under 400 ms) are dropped. Existing projects wait until after GA for multi-stage screening. | MAIN/docs/features/screening-profiles/README.md:172-208, 212-217 | §5 Q9. Add the metrics to the R3a/R3b acceptance criteria. |
| PH-24 | Minor | PLAN prisma-amendments.md:101-110; open-questions:91 (Q-22); contracts.md:378 | FEAT-009's reconciliation pool settings (default "reconcile when reasons exist", bypass criteria, all studies option) and its rule for trimming disagreed sub-reasons are not mapped. | MAIN/docs/features/screening-annotations/README.md:348-432 | Use them as inputs to the profile reconciliation settings and amendment E/Q-22. |
| PH-25 | Minor | PLAN acceptance-criteria.md:50; contracts.md:424-428 | The March export analysis found about 0% meaningful coverage and no blinding check. Some tests exist now, but none asserts that blinded output hides identities (UNVERIFIED beyond a scan of the export tests). AC-ALL-02 assumes regression protection. Streaming partial-response is relevant to manifests, and #3335 D11 (only the requester or an admin may download an export) is missing. | MAIN/docs/planning/data-export-analysis.md:240-264, 490; HO/2026-09-08-authorization-3335/PLAN.md:66 | Make characterisation tests (format × blinding × seed project) a precondition at R0. Add D11 to C10/C11. |
| PH-26 | Minor | PLAN open-questions:79 (Q-29), 84 (Q-32); contracts.md:376 | FEAT-006 decisions superseded silently: D12 (rationale can be made required), D15 (no reconciliation bypass) against Q-29's "no task", D19–D27 (reference-first sharing, four ownership scopes, an Organisation aggregate, a community publish flag) against copy-only templates, D33/D35 (later reconcilers override) against "first publisher wins". | MAIN/docs/features/reconciliation/design-decisions.md:344, 977, 980, 984-993, 998-1000 | Add rows to register §2. Cite D15 and D35 in Q-29 and C9. |
| PH-27 | Minor | PLAN domain-model.md:43-45, 80; decision-register.md:172 | System-wide templates (SET1's default profile templates; FEAT-014 templates with no creator) break "every aggregate carries its project ID". Template ownership scope and who curates them are undefined. | MAIN/docs/features/project-templates.md:46-60 | Add an owner scope to DefinitionTemplate (§5 Q11). Build the new seed projects from templates. |
| PH-28 | Note | PLAN decision-register.md:121 (DP4) | Screening keyword lists live on the Project and the Screening Settings page. Their home after profiles take over (DP4) is not stated. | MAIN/docs/features/screening-keyword-highlighting/README.md:59, 236 | Decide profile-owned or project-owned at F5. |
| PH-29 | Minor | PLAN integrated-plan.md:279-293 | R0 designs a new compatibility floor and ignores three existing ones: the writer floor in SyRF.Mongo.Common (fails closed unless every instance is at the minimum version), ADR-019's storage-version tripwire with its allowlist guard, and ADR-011's writer-floor precedent. | MAIN/src/libs/mongo/SyRF.Mongo.Common/ServiceVersionFloor.cs; MAIN/docs/decisions/ADR-019-materialized-statistics-async-point-fold.md:50-54 | Reuse them in C16. |
| PH-30 | Note | PLAN contracts.md (C1, C9) | ADR-009 (approved; domain vs application services) and ADR-008 (draft; absolute UTC timestamps, Quartz integration tests) are not referenced, though the engine and the 7-day expiry depend on them. | MAIN/docs/decisions/ADR-009-domain-vs-application-service-classification.md:12-40; …/ADR-008-review-access-state-and-timing.md:54-116 | Cite both in F1/F4 ADRs. Add Quartz expiry tests to the R4a acceptance criteria. |
| PH-31 | Note | PLAN ui-coverage-comparison.md:177-202 | Source classification, external counts, the duplicate review queue, the merge wizard, dedup jobs and adoption jobs have no place in Library, Searches or Processing. Processing is defined as read-only history for three job families. | MAIN/docs/features/study-management/README.md:176-178 | Place them in C17 with the FEAT-018 owner. |
| PH-32 | Note | PLAN acceptance-criteria.md:172, 278 | AC-R2a-19 and AC-R4a-13 invent new budgets instead of using AF2's perf gate (first interactive under 1,500 ms, edit p95 under 16 ms, category switch under 250 ms, mounting caps). | MAIN/docs/planning/annotation-form-perf-baseline.md:95-100 | Extend that gate with history-panel and N-candidate fixtures. |
| PH-33 | Note | PLAN open-questions:123 (E21) | SL1 says autosave keeps "draft changes/history", and the ledger lists autosave history as open engineering. E21's single draft per session cannot restore earlier autosave states. QM v2 ADR-011's two-level drafts (an autosave trail with retention), D010 (concurrent admin editing with presence) and the training-rounds brief are unused. The 28 September handover's "superseded approaches to avoid" list is also not carried. | pr3617 review-form-owner-decisions-2026-10-02.md:42, 342; MAIN/.local/qm-designer-handover/04-versioning-and-publishing/ADR-011-qm-v2-two-level-draft-and-formal-versioning.md:47-54; MAIN/docs/planning/qm-v2-context/qm-v2-architecture-and-knowledge.md:38; MAIN/.local/qm-designer-handover/06-adjacent-features/training-rounds.md:17-40 | Decide in E21 whether a draft trail is kept. Add multi-admin editing to C4. Disposition training rounds (§5 Q12). |
| PH-34 | Note | PLAN source-status-inventory.md:297 | Live state has moved: #3956 has merged (main commit 86a3caa10). main is now at 0f5c61073 with FEAT-024 slice 7 documents. |
git log in MAIN |
Refresh before G0. |
| PH-35 | Note | PLAN open-questions:163 (U17) | The v4 page records a decision with one key (I/E) and auto-advances. That has to be reconciled with derived decisions confirmed only on submit (DP3) and with exclusion reasons (DP5). | HO/2026-09-21-stage-review-design/design_handoff_stage_review_page/README.md:85, 105 | Add to U17. |
4. Earlier ideas the plan should adopt¶
- FEAT-024's write benchmark and ADR-019's gate (b) as the acceptance test for canonical commits, and its asynchronous fold pattern for any per-project derivation (PH-01).
- The generated eligibility truth table and its row-by-row Mongo tests, as C6's conformance suite (PH-04).
- FEAT-020's single rules file, fixtures and code generation, plus FEAT-017's log-only rollout. Measure how far the front end and back end diverge on legacy data before R2a enforces Complete (PH-07).
- FEAT-003's per-session reconstruction categories and 4-step decision flow, and FEAT-001's breaking-change transitivity and stored resolved-question set, as the impact manifest and U6 structure (PH-18).
- FEAT-007's admin-initiated screening adoption and its measurable success metrics; FEAT-008's filter simplifier, cycle check and select-next budget (PH-23, PH-05).
- FEAT-009's bypass criteria and reason trimming for profile reconciliation (PH-24).
- The writer floor and storage-version tripwire already in the codebase, for R0 (PH-29).
- Staged import (#2612) and the May incident's heartbeat, watchdog and stall rules as the standard for every long-running operation: publication phase 2, adoption backfill, retroactive dedup, as-of exports (PH-09).
- FEAT-014 templates to build the six proposed seed projects with less code (PH-27).
- The approved AF2 four-state readiness model, "review slot" wording, v4's "What's new" tour and v10's "What's different from released SyRF" page for change communication at GA (PH-19).
- The SSI Community Steering Group as the standing user-testing panel, plus an independent WCAG audit at GA (PH-12).
- Training rounds modelled as an admission prerequisite step scored against gold (PH-33).
5. Questions for Chris¶
- Deletion vs history. ADR-014 (12 August) physically deletes a search's Studies after a 24-hour grace period. Amendment J (3 October) keeps Citation history. Which governs for admitted projects? Recommendation: withdrawing a search hides its Studies but keeps Citations and canonical evidence. Deleting a whole project keeps ADR-014's physical removal with a tombstone. Physical cleanup of files and PDFs is unchanged.
- Does an autosaved draft hold a review slot? Recommendation: no. The slot is secured on the first explicit Save, as today. The draft survives if the slot lapses. On return, the reviewer keeps the draft, can save it as surplus where target enforcement is off, and gets an honest message.
- Eligibility D8 in the step model. Recommendation: (3) a disabled stage blocks only its own route; a shared session stays reachable through an active stage. (4) Hiding excluded saved work becomes a display sub-setting of EW1. (5) R4a lets an authorised admin start reconciliation before readiness, with a warning. (1) Removal becomes a versioned withdrawal. (2) Claim release carries over unchanged.
- Funder deliverables. Should NC3Rs' outstanding "in-app reconciliation (qualitative)" change the order of work? Recommendation: do not build a reconciler on the legacy model (it would create gold that is not a snapshot). Instead, start F4 in W1, map each NC3Rs item to its release, and confirm with the funder which release satisfies it. The contract's current status is UNVERIFIED.
- Blinding and random serving, given the EoI's claim that they are not optional. BL1 says blinding is stage-owned; may that stage setting turn blinding off? Recommendation: candidates are always blinded; the stage chooses only the alias scheme. Unmasking goes through the audited export disclosure contract. Random serving stays the default; explicit assignment is an audited exception.
- Importing answers from other tools (FEAT-004). In scope? Recommendation: yes, as a lane after R2a. Imported answers get their own provenance kind and are excluded from independence statistics. They count toward the target only when mapped to a SyRF reviewer at import. They never become gold automatically.
- Completed work from disabled members. Recommendation: it keeps counting and stays in reconciliation, because evidence is never erased. An audited admin action can exclude a reviewer's contributions from a form.
- Routing studies by answer values (for example, "only rat studies go to stage B"). Recommendation: in full scope as a lane after R4a, expressed as a step-dependency rule on gold values; not required for GA.
- Early screening-profile adoption for existing projects. Recommendation: allow admin-initiated adoption of screening-only, unreconciled stages after R3b, using a generated manifest and reversible until the first canonical write.
- Stale-answer acknowledgement (FEAT-001 D54/D55). Recommendation: replace it with RE2's non-blocking warning and Complete anyway; drop the per-project enforcement levels.
- Template ownership. Recommendation: CAMARADES-curated system templates under an application role; project templates stay private; cross-project publishing deferred.
- Training (calibration) rounds. Recommendation: after GA, but keep a "passed training" admission hook in C6 now.
Critical Files for Implementation¶
- /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/contracts.md
- /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/open-questions-and-assumptions.md
- /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/decision-register.md
- /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/source-status-inventory.md
- /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/acceptance-criteria.md